Join us at Tampa Bay API Security Summit 2025!
Join us at Tampa Bay API Security Summit 2025!
Join us at Tampa Bay API Security Summit 2025!
Join us at Tampa Bay API Security Summit 2025!
Join us at Tampa Bay API Security Summit 2025!
Join us at Tampa Bay API Security Summit 2025!
閉じる
プライバシー設定
当社は、ウェブサイトの運営に必要なクッキーおよび類似の技術を使用しています。その他のクッキーは、お客様の同意がある場合にのみ使用されます。「同意」をクリックすると、当社によるクッキーの使用に同意することができます。どのデータが収集され、どのようにパートナーと共有されるかについての詳細は、当社のプライバシーとクッキーに関するポリシーをご覧ください。 クッキーポリシープライバシーポリシー
当社は、クッキーを使用して、お客様のデバイスの特性や特定の個人データ(IPアドレス、ナビゲーションの使用状況、位置情報データ、または一意の識別子)などの情報へのアクセス、分析、保存を行います。お客様のデータの処理にはさまざまな目的があります。アナリティクスクッキーを使用すると、当社のパフォーマンスを分析してお客様により良いオンライン体験を提供したり、キャンペーンの効果を評価したりすることができます。パーソナライゼーションクッキーを使うと、利用状況に応じたオファーやサポートを提供して、当社ウェブサイトをカスタマイズすることができます。最後に、広告クッキーは、ソーシャルメディアやインターネット上でターゲットを絞った広告を配信するためのオーディエンスリストを作成するために、お客様のデータを処理する第三者企業によって設定されます。各ページの下部にあるリンクを使用して、いつでも自由に同意を付与、拒否、または撤回することができます。
ありがとう!提出物が受理されました!
おっと!フォームの送信中に問題が発生しました。
Whitepaper

Q2-2022 API Vulnerability & Exploit full report

In Q2-2022, the Wallarm Research team found 184 API-related vulnerabilities out of a total of 88,241 records examined, an increase of +268% over Q1.

This research over the last two quarters shows that the volume of API vulnerabilities has more than doubled and time to exploit has halved. Check out the results in this report and learn why you need to set data defensible remediation policies that engineers and executives will support – particularly as API vulnerabilities continue on their exponential growth trajectory through 2022.

Thanks for filling out the form!
The resource link will open in the new tab. If its not, please follow this link
Oops! Something went wrong while submitting the form.

Key Take-Aways

Based on this analysis of Q2-2022 API vulnerabilities and the trends we’ve seen over H1-2022, we recommend you consider the following when assessing your API security:

Growth Rate. API-specific vulnerabilities reported in Q2 grew by 268% to 184 total (or about2 per day) – which suggests an ever-increasing risk in your API portfolio.

Criticality. The number of Critical and High risk API vulnerabilities remain dramatically high, in the 60% range – which also indicates that extra vigilance is needed.

Attack Vectors. Injections (OWASP A03 / API8) are now the highest risk for APIs, ahead of BOLA by all metrics (number of issues discovered, exploitability, and severity) – which points to the need for more pre-release testing.

Depth & Breadth. Concurrently we’re seeing more “most dangerous” CWEs being found with broader (more vendors, more products) and deeper (e.g., attacks against Dev Tools) impact– which emphasizes the need.

Exploitability. 33% of the API vulnerabilities reported in Q2 were almost immediately exploited, with POCs published within a median of 2-1/2 weeks – since these exploits are probably underreported, this illustrates the need for run-time protection.

Impartiality. Open Source software is not necessarily less vulnerable than commercial software, and the nature of the vulnerabilities in them differ – which means that neither should be treated as special when it comes to vulnerability management.

Trusted by the world’s most innovative companies:

15 min

To unboard and view secutity results
“I needed cloud security tooling that could get me visibility fast. Wallarm answers all my visibility needs within minutes — across multiple clouds.”
Miro Logo

500K

per year in const savings
“With Wallarm, we've been able to scale API protection to the scale we need and manage with our infrastructure as a code approach.”
Rappi Logo

100%

visibility into multi-cloud environments
“With Wallarm, we've been able to scale API protection to the scale we need and manage with our infrastructure as a code approach.”
Dropbox Logo
Panasonic Logo
Victoria's Secret Logo
Miro Logo
Gannet Logo
Dropbox Logo
Rappi Logo
Wargaming Logo
Semrush Logo
Tipalti Logo
UZ Leuven Logo

Ready to protect your APIs?

Wallarm helps you develop fast and stay secure.