industry news
Subscribe Now

Flexera Reimagines Open Source Vulnerability Detection with FlexNet Code Insight

Secunia Advisories Now Integrated into Open Source License and Vulnerability Detection Platform, Reducing Risk that Suppliers Will Ship Vulnerable Open Source Components to Their Customers

ITASCA, Ill., Dec. 18, 2017 (GLOBE NEWSWIRE) — Flexera, the company that’s reimagining how software is bought, sold, managed and secured, today announced that its world-renowned Flexera Software Vulnerability Database is now integrated into FlexNet Code Insight – the market-leading open source license and vulnerability detection platform.  The integration gives software developers unparalleled insight into vulnerabilities that may lurk within their open source code, and the ability to remediate those vulnerabilities before shipping their products to customers.

“Finding open source security vulnerabilities in packages, all the way to deep dependencies, has always been a priority for Flexera,” said Jeff Luszcz, Vice President of Product Management at Flexera.  “This integration gives developers access to the deepest and most trusted vulnerability database in the world to help them minimize vulnerability risk.  Our customers can leverage the combined strength of FlexNet Code Insight, powered by the National Vulnerability Database (NVD) and the Flexera Software Vulnerability Database, to significantly reduce the risk window between identifying and remediating vulnerabilities – before exploitation leads to costly breaches.”

Better Vulnerability Data Helps Close the Risk Window

The use of open source components in software development is skyrocketing.  A decade ago, developers were using less than 100 open source libraries per release.  Today, some industries are using more than 3,000.  As open source dependency increases, software suppliers need to help ensure a safer software supply chain by truly understanding the vulnerability risk and compliance requirements they’re inheriting from the open source code they use.

As many companies have discovered the hard way, there’s an unacceptable risk window that persists between the discovery of a software vulnerability and when the patch is successfully installed.  According toFlexera’s Vulnerability Review 2017, 17,147 vulnerabilities were recorded in 2,136 products from 246 vendors.  81 percent of those vulnerabilities had patches available on the same day as disclosure.  But, on average, it takes companies 186 days to completely install those patches1.  This risk window gives hackers plenty of opportunity to exploit vulnerabilities, and perpetrate attacks with costly consequences to businesses.

Flexera Software Vulnerability Database powers its market-leading Software Vulnerability Management solutions.  By integrating this powerful database with FlexNet Code Insight, Flexera gives developers unparalleled ability to protect themselves and their customers from the potentially devastating effects arising when open source vulnerabilities are exploited.

With today’s announcement, FlexNet Code Insight is narrowing the risk window – providing comprehensive intelligence on discovered vulnerabilities.  Organizations can now protect their products – and their customers – faster by identifying vulnerabilities as soon as they’re made public.  Armed with better information, sooner, they’re then in a much better position to assess, prioritize and patch vulnerabilities before they’re exploited.  Additionally, FlexNet Code Insight is able to alert development and security teams when new vulnerabilities are discovered in already shipping software.

“After the Equifax breach, which was caused by an exploitation of the Apache Struts 2 open source component, the world now understands the dire risks that occur when software suppliers unknowingly ship vulnerable components in their products, endangering the software supply chain,” added Luszcz.  “Flexera now offers the most powerful tools available to help suppliers avoid that liability.”

Follow us on…

About Flexera

Flexera is reimagining the way software is bought, sold, managed and secured.  We view the software industry as a supply chain, and make the business of buying and selling software and technology asset data more profitable, secure, and effective.  Our Monetization and Security solutions help software sellers transform their business models, grow recurring revenues and minimize open source risk.  Our Vulnerability and Software Asset Management (SAM) solutions strip waste and unpredictability out of procuring software, helping companies buy only the software and cloud services they need, manage what they have, and reduce compliance and security risk.  Powering these solutions and the entire software supply chain, Flexera has built the world’s largest and most comprehensive repository of market intelligence on technology assets.  In business for 30+ years, our 1200+ employees are passionate about helping our 80,000+ customers generate millions in ROI every year.  Visit us at www.flexera.com.

About Secunia Research@Flexera

Secunia Research at Flexera is a research team with globally recognized expertise in discovering, verifying, testing, validating and documenting vulnerabilities on tens of thousands of applications and systems.  Our experts work under strict ethical guidelines and collaborate with the research community and software producers to guarantee the quality of the vulnerability information we document.

Leave a Reply

featured blogs
Apr 24, 2024
Diversity, equity, and inclusion (DEI) are not just words but values that are exemplified through our culture at Cadence. In the DEI@Cadence blog series, you'll find a community where employees share their perspectives and experiences. By providing a glimpse of their personal...
Apr 23, 2024
We explore Aerospace and Government (A&G) chip design and explain how Silicon Lifecycle Management (SLM) ensures semiconductor reliability for A&G applications.The post SLM Solutions for Mission-Critical Aerospace and Government Chip Designs appeared first on Chip ...
Apr 18, 2024
Are you ready for a revolution in robotic technology (as opposed to a robotic revolution, of course)?...

featured video

How MediaTek Optimizes SI Design with Cadence Optimality Explorer and Clarity 3D Solver

Sponsored by Cadence Design Systems

In the era of 5G/6G communication, signal integrity (SI) design considerations are important in high-speed interface design. MediaTek’s design process usually relies on human intuition, but with Cadence’s Optimality Intelligent System Explorer and Clarity 3D Solver, they’ve increased design productivity by 75X. The Optimality Explorer’s AI technology not only improves productivity, but also provides helpful insights and answers.

Learn how MediaTek uses Cadence tools in SI design

featured paper

Designing Robust 5G Power Amplifiers for the Real World

Sponsored by Keysight

Simulating 5G power amplifier (PA) designs at the component and system levels with authentic modulation and high-fidelity behavioral models increases predictability, lowers risk, and shrinks schedules. Simulation software enables multi-technology layout and multi-domain analysis, evaluating the impacts of 5G PA design choices while delivering accurate results in a single virtual workspace. This application note delves into how authentic modulation enhances predictability and performance in 5G millimeter-wave systems.

Download now to revolutionize your design process.

featured chalk talk

Digi XBee 3 Global Cellular Solutions
Sponsored by Mouser Electronics and Digi
Adding cellular capabilities to your next design can be a complicated, time consuming process. In this episode of Chalk Talk, Amelia Dalton and Alec Jahnke from Digi chat about how Digi XBee Global Cellular Solutions can help you navigate the complexities of adding cellular connectivity to your next design. They investigate how the Digi XBee software can help you monitor and manage your connected devices and how the Digi Xbee 3 cellular ecosystem can help future proof your next design.
Nov 6, 2023
22,399 views