Customization a Weakness in App Security

on Thu, July 20, 2006
Tweet it!
Email
Digg
Share this article
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

CIO

The customization of off-the-shelf software is the weakest link in application security. This is particularly true for widely used enterprise products such as SAP and Oracle, according to Gartner Research Director Rich Mogull.

He said the massive amounts of customization required to get products from both SAP and Oracle to perform ideally means that IT managers have no fail-safe point if some of the code creates vulnerabilities. As a result, managers have to cherrypick through code to find their own mistakes as opposed to downloading a patch from a vendor.

Speaking at the Gartner IT Security Summit in Sydney last week, Mogull said this problem has created custom vulnerabilities.

"Custom code does not undergo the same QA testing as commercial code does," Mogull said.

"All major applications, be they an application server or off-the-shelf software, is implemented mostly through custom code, and this is one of the biggest issues facing major application security. But what is even worse about this is any vulnerability you have in your system is yours, and no one else will find it but you.

"The advantage of off-the-shelf programs is that vulnerabilities are managed by vendors through patch update, but typically the security models that we do see featured in some applications are limited compared to the amount of customization done on applications to get them running."

Mogull added PeopleSoft had "pretty good" security models compared to other major enterprise applications, and since the Oracle purchase some of that knowledge is "seeping into other areas of Oracle"; however, the intentional ease of use within SAP applications has given IT managers free rein to make critical security mistakes.

"SAP, we find, is an incredibly flexible application with large amounts of custom code, which may be why some implementation projects take two years and is built on something called WebAS [application server] with two programming languages, J2EE and the other a programming language specific to SAP [ABAP]," Mogull said.

"Because we have this mixture of code and an application server on the back end, any SAP implementation is effectively a custom-code implementation that needs a secure development lifecycle.

"Oracle does tend to be a bit more off-the-shelf than SAP, and the Oracle product line is huge as it has PeopleSoft, Siebel and JD Edwards, but the problem is it has yet to integrate it. The identity management line is still in the integration process; there is no consistent security model across all products."

Mark Frear, director of business development for SAP Netweaver, said the vulnerabilities introduced through custom code are related to software development quality and the ethos of the company doing the coding.

Continue Reading

$firstKeyword

Get up to speed on mobile security.

Learn More »
Loading...
Most Recent Security Stories
The path to creating a secure application begins by rigorously testing source code for all vulnerabilities and ensuring that use of the application does not compromise or allow others to compromise data privacy and integrity.
The reasons for outsourcing application development are many and varied. Outsourcing can be a cost effective and efficient solution to the demand for new and specialized applications in todays Internet-based marketplace. It is absolutely critical, however, that the team responsible for evaluating the outsourced application makes security one of its principal criteria prior to acceptance of each release.
The path to creating a secure application begins by rigorously testing source code for all vulnerabilities and ensuring that use of the application does not compromise or allow others to compromise data privacy and integrity.
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many dont understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle.
Watch an online demo of iPrism and you'll get a $20 Amazon gift card as our way of saying thanks.
Online fraud is a non-stop threat to organizations around the globe, and cybercriminals have no intention of slowing down the pace. Also, global are likely to have an impact on the evolution of cybercrime. Read this special online fraud report for information about the latest online fraud trends and what to expect and prepare for in the future.
Key IT Security & Authentication Concerns for 2010
Data protection is a bigger challenger for small and midsize businesses. You need to protect sensitive data, but la...
Privacy and Data Protection Practices
Moderated by CSO Publisher, Bob Bragdon, hear from this esteemed panel as they share practical approaches to simpli...
Avoid common pitfalls and learn strategies for ensuring a successful PCI audit from information security and compli...
Protecting critical data is now the imperative at most every organization. As more and more laws are passed and reg...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Sponsored Links

Simplifying Risk Management: Is Your Company Measuring Up?

Attend Microsoft's Windows 7 Virutal Event for a change to win a Microsoft Zune HD. Register Now!

Ready to create safe, business class social networking tools? View Now

Let Progress Software help your business make progress.

Register for more Windows Enterprise Webcasts today.

Entrust IdentityGuard  Strong Authentication for your Enterprise

Supercharge Your End Users with Desktop Virtualization

Take the Netezza TwinFin TestDrive!

Best Practices to Reduce IT Operational Costs

Maximizing efficiencies with unified communications.

Taking the Service Desk to the Next Level

Getting ready to upgrade to Windows 7? Attend Microsoft's Virtual Event on 4/22 for all the tools you'll need. Register Now!

Read report on how to improve decision making with business analytics.

Dynamic Virtual Client: Whats in store for client technology going forward?

The ISP that focuses exclusively on information security? SecureWorks.

Does your IDS really work? Find out with a free Endace Audit

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Enterprise search helps employees get more done. Get the facts from Google.

Real-world testing ranks Trend Micro #1 against malware. See results.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Trend Micro ranked #1 against real-world malware. Read more.

How Healthcare CIOs Achieve a High-Performance Emergency Department

Webcast: Solve Your Data Visualization Needs with Open Source BI

Webcast: Delivering the Enterprise-Ready Cloud

Ensure cost effective application delivery. Learn More.

Trend Micro ranked #1 against real-world malware. Read more.

March 31st Webcast: "Product Development and the Cross-Functional Team"

Get to know Supermicro. Business-optimized server solutions.

Google Webinar: Why Cloud-Based Security and Archiving Make Sense

HP pays back. Trade in your old printer and get up to $1000

Counting Up the End User Benefits of Desktop Virtualization

Build a smart, practical path to the internal cloud.

Verint Systems. Discover the Power of Intelligence in Action"

Efficiency goes up. Costs come down.

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Midsized company CIOs and experts connect at infoBOOM!

Core" i5 vPro" Processor: Control meets cost savings in the most intelligent PC processors ever!

Article: The Dynamic Virtual Client offers thin client advantages with rich client user experience & mobility.

Manage limitless content todayread EMCs 15-minute guide to ECM.

HP Exstream. Get a Free Document Assessment for Financial Services.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

See why ShoreTel is named best overall VoIP provider by Nemertes Research

Turn your desk phone and mobile phone into one with Sprint Mobile Integration.

Stay informed with custom newsletters from Tech Dispenser

Get ready for your Windows 7 upgrade at this live, virtual event. Register Now!

Selecting the Right Reporting Technology

An IT Leadership Action Plan for the Economic Recovery

Consolidate data centers and lower IT service costs. Learn How.

WAN optimization techniques significantly improve application performance. Read More.

Resource Center