Application Security Risk 2017
The OWASP top ten has been changed and following list is the updated.
- A1:2017 – Injection
- A2:2017 – Broken Authentication
- A3:2017 – Sensitive Data Exposure
- A4:2017 – XML External Entities (XXE)
- A5:2017 – Broken Access Control
- A6:2017 – Security Misconfiguration
- A7:2017 – Cross Site Scripting (XSS)
- A8:2017 – Insecure Deserialization
- A9:2017 – Using Component with Known Vulnerability
- A10:2017 – Insufficient Logging & Monitoring