The latest quarterly review and analysis of API vulnerabilities and exploits is in. Our initial take had us thinking it was smooth sailing for the state of API vulnerabilities in Q3—or was it just a lull in the storm?
As it turns out, it’s neither.
Read on to learn more about Wallarm’s analysis of API vulnerabilities in Q3-2022—and be sure to attend our upcoming webinar on Thursday, November 10 at 11 AM PT where we’ll present all our findings. Register Now to reserve your seat!
At first blush, this quarter’s data appear to be a story about API vulnerabilities leveling off: the number of API vulnerabilities and impacted vendors – metrics that saw huge jumps in the Q2 API Vulnerability Report – were basically unchanged during Q3. This combined with virtually unchanged CVSS scores (both average and % in the critical or high range) had Q3 looking like a nothingburger.
But digging deeper into the data revealed that these still waters run deep.
Key Findings
All these findings will have significant implications on your organization’s API security program.
Analysis Path
As per usual, we analyzed the data to look for trends and insights from a variety of perspectives, including software type, vendor, CVSS scores, CWEs and both OWASP Top-10 (2021) for web apps and OWASP API Security Top-10 (2019). We also dug deeply into publicly disclosed exploit PoCs to extract payloads and validate if any threats have moved from a theoretical to an actual risk.
So how did we reach these conclusions? Here’s a brief look at the analysis path:
Infographic
For more highlights from the final report, look at our Q3-2022 API ThreatStats™ Report infographic. We hope you find it interesting and useful, and that it helps you improve your API vulnerability management and security posture.
Deep-Dive Webinar
To learn more, we invite you to attend our upcoming webinar on Thursday, November 10th. In this live-stream event, Ivan Novikov, CEO & co-founder of Wallarm and noted security researcher, will take a deep look at the Q3 API vulnerability and exploit data, and discuss the implications to your organizational risk and your cyberdefenses. And of course, he’ll be answering your questions along the way!