In 2022, the most important software weakness discovered through static analysis of all development languages worldwide was found to be in CRLF injection, representing nearly 65 percent of the flaws. Cryptographic issues and information leakage constituted other commonly discovered flaws, reaching each around 60 percent of the flaws. Static analysis is a method of computer program debugging, completed by examining the code without executing the program. This is the reasons why static analysis requires a high understanding of code structure.
Most important software weaknesses discovered through static analysis worldwide in 2022
According to the source, the methodology of the study consisted of full historical data from Veracode services and customers:
- 759,445 applications that used all scan types;
- 1,262,147 dynamic analysis scans;
- 7,522,989 static analysis scans;
- 18,473,203 software composition analysis scans.
All the scans produced:
-86 million raw static findings;
-3.7 million raw dynamic findings;
-8.5 million raw software composition analysis findings.
Profit from the additional features of your individual account
Currently, you are using a shared account. To use individual functions (e.g., mark statistics as favourites, set
statistic alerts) please log in with your personal account.
If you are an admin, please authenticate by logging in again.
Learn more about how Statista can support your business.
Veracode. (January 12, 2023). Most important software weaknesses discovered through static analysis worldwide in 2022 [Graph]. In Statista. Retrieved December 22, 2024, from https://www.statista.com/statistics/1322608/global-software-flaws-static-analysis/
Veracode. "Most important software weaknesses discovered through static analysis worldwide in 2022." Chart. January 12, 2023. Statista. Accessed December 22, 2024. https://www.statista.com/statistics/1322608/global-software-flaws-static-analysis/
Veracode. (2023). Most important software weaknesses discovered through static analysis worldwide in 2022. Statista. Statista Inc.. Accessed: December 22, 2024. https://www.statista.com/statistics/1322608/global-software-flaws-static-analysis/
Veracode. "Most Important Software Weaknesses Discovered through Static Analysis Worldwide in 2022." Statista, Statista Inc., 12 Jan 2023, https://www.statista.com/statistics/1322608/global-software-flaws-static-analysis/
Veracode, Most important software weaknesses discovered through static analysis worldwide in 2022 Statista, https://www.statista.com/statistics/1322608/global-software-flaws-static-analysis/ (last visited December 22, 2024)
Most important software weaknesses discovered through static analysis worldwide in 2022 [Graph], Veracode, January 12, 2023. [Online]. Available: https://www.statista.com/statistics/1322608/global-software-flaws-static-analysis/