• Home
  • Research
  • What We Offer
  • Who We Are
  • Blog
  • Your cart is empty.
  • Log in
  • Purchase
  • Free Sample
  • Contact
  • Recent Entries
  • Get Custom Feeds
Team Blog
Thomas

Beware Drupal, Joomla! plug-in vulnerabilities

Added By Kas Thomas at 1-Mar-2010 |

IBM has released its IBM Security Solutions X-Force 2009 Trend and Risk Report, and the news for users of popular WCM platforms Drupal, Joomla!, TYPO3, and WordPress is decidedly mixed.

According to IBM's research, while Apache and PHP account for only 0.4 percent and 0.6 percent (respectively) of total reported vulnerabilities, Drupal accounted for 2.7 percent and Joomla! accounted for 2.6 percent. TYPO3 and WordPress fared somewhat better, at 1.5 and 0.4 percent, respectively.

But the more ominous news has to do with patches for security problems involving plug-ins. A whopping 80 percent of the vulnerabilities reported for Joomla! plug-ins (against 13 percent for Drupal plug-ins) had no available security patches by year's end. That compares to 8 percent of Joomla! core system vulnerabilities that had no known patch, and 18 percent of Drupal core vulnerabilities with no patch. If you're a TYPO3 user, you'll find that 51 percent of plug-in vulnerabilities have no patch (versus just 5% of core system gotchas), while with WordPresss the unpatched plug-in flaws come to 57 percent, versus 13 percent for core.

Bottom line: Systems that are heavily reliant on plug-ins are more apt to have security vulnerabilities for which there is no known patch. Why is this?  Even frequently-used plug-ins are not always actively maintained and enhanced by their original developers.  Our Web CMS evaluation research cites some specific examples across several platforms. 

Next steps: Get a free research sample or purchase complete vendor evaluations to obtain immediate access.

Categories: Collaboration & Community Software, Web Content Management, Open Source, Selecting Technology, Drupal, Joomla!, TYPO3

Tweet

My Research

Remember MeForgot password?

Not a subscriber? Learn about our subscriptions

Categories

Channel

  • Collaboration & Community Software (161)
  • Component Content Management (79)
  • Digital Asset Management (141)
  • Enterprise Content Management (615)
  • Evaluating SharePoint (131)
  • Portals and Content Integration (351)
  • Search and Information Access (297)
  • SharePoint Across the Enterprise (68)
  • Web Analytics (172)
  • Web Content Management (860)

Analyst

  • Adriaan Bloem (99)
  • Tony Byrne (986)
  • Apoorv Durga (34)
  • Jarrod Gingras (49)
  • Alan Pelz-Sharpe (229)
  • Theresa Regli (88)

Topics

  • Asia-Pacific Marketplace (5)
  • Building Business Case (237)
  • Cloud Computing (10)
  • E-Discovery (13)
  • European Marketplace (30)
  • Governance (29)
  • Green Computing (1)
  • Implementation (324)
  • Industry Events (20)
  • Industry Standards (197)
  • Information Architecture (162)
  • Intranets (14)
  • Marketplace at Large (918)
  • Mobile Computing (5)
  • Open Source (128)
  • Selecting Technology (911)
  • Services Oriented Architecture (9)
  • Software-as-a-Service (26)
  • Usability (5)
  • Vendor Viability & Financials (198)
  • XML (93)

Industries

  • Energy (4)
  • Finance (13)
  • Government (34)
  • Health Care (12)
  • Higher Ed (20)
  • Legal (18)
  • Manufacturing (7)
  • Pharma (6)
  • Publishing-Media (17)
  • Retail (9)

Dates

  • 2010 (207)
  • 2009 (292)
  • 2008 (345)
  • 2007 (294)
  • 2006 (206)
  • 2005 (222)
  • 2004 (109)
  • 2003 (100)
  • 2002 (97)
  • 2001 (44)

Have Questions?

Sales & Customer Support

+1 800 325 6190 (USA)+44 (0) 20 3318 1911 (UK)+1 617 340 6464 (Int'l)sales@realstorygroup.com support@realstorygroup.com

All other inquiries: info@realstorygroup.com

Copyright, 2001 - 2010, Real Story Group. All rights reserved.

  • Contact Us
  • Copyright Policy
  • Privacy Policy
  • Terms of Use

Vendor Evaluations

  • Collaboration & Community Software
  • Digital Asset Management
  • Enterprise Content Management
  • Portals & Content Integration
  • Search & Information Access
  • SharePoint Across the Enterprise
  • Web Analytics
  • Web Content Management

What You Get

  • Vendor Evaluations
  • Advisory Papers
  • One-on-One Advice
  • Online Education
  • Consulting Services
  • Free Research Sample
  • Purchase Now

Need Help?

  • Research & Advisory
       Overview
  • Talk to an Expert
  • FAQs
  • Customer Support
  • Contact Sales Team

Who We Are

  • We're Different
  • Our Team
  • Media
  • Customer List
  • Events
  • Contact Us

Get the real story via our bi-weekly newsletter.

Follow us on: RSS twitter

Log In

Remember MeForgot password?