Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News
    • Blogs
    • Security Watch

    IBM Corrects Security Vulnerability Numbers in Threat Report

    Written by

    Brian Prince
    Published September 1, 2010
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      IBM has revised some of the findings in its “X-Force 2010 Mid-year Trend and Risk Report” after complaints that its vulnerability tallies were inaccurate.

      “After we released our trend report…we received feedback from two software vendors regarding the severity and remedy information for some of the vulnerabilities behind this chart,” Tom Cross, manager of IBM’s X-Force Advanced Research Team, blogged Aug. 28. “This sort of input is crucial for us – with more input from software vendors about vulnerability information we get greater accuracy in our snapshot of the industry. As a consequence of this feedback, we have manually reassessed the CVSS scoring, remedy information, and vendor information for every vulnerability that impacted the percentages that appear in this chart.”

      The latest information drastically altered the rankings of Google and Sun Microsystems (which is listed separately in the report from Oracle), to the tune of Sun dropping from the vendor with the most unpatched vulnerabilities to the middle of the pack. Google, which was initially reported to have left 33 percent of its critical vulnerabilities unfixed, was found to have patched all of its critical vulnerabilities.

      “We learned after investigating that the 33 percent figure referred to a single unpatched vulnerability out of a total of three — and importantly, the one item that was considered unpatched was only mistakenly considered a security vulnerability due to a terminology mix-up,” blogged Adam Mein of Google’s security team. “As a result, the true unpatched rate for these high-risk bugs is 0 out of 2, or 0 percent.”

      The initial vulnerability tallies also listed Sun as having 24 percent of its vulnerabilities unpatched – this was changed to eight percent. Other changes include Mozilla going from 21 percent to 17; Apple from 13 to 12; Linux from eight to three; IBM from 10 to 9 and Hewlett-Packard (HP) from seven percent to four.

      The list also was revised to show IBM actually leading the way in terms of the number of unpatched critical bugs, with 29 percent.

      “Every vulnerability page in the database has always included our e-mail address for corrections and additions, and we work constantly to develop and maintain relationships with other software companies to coordinate vulnerability information,” Cross blogged. “Efforts are currently underway within the software industry to develop standards for reporting of vulnerability and remedy information. We believe that those standardization efforts hold the key to making sure that consumers always have the latest information from software vendors about vulnerability disclosures affecting their products.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×