Micro Focus Fortify and Sonatype Deliver 360 Degree View of Application Security Brochure
Micro Focus Fortify and Sonatype Deliver 360 Degree View of Application Security Brochure
Micro Focus Fortify and Sonatype Deliver 360 Degree View of Application Security Brochure
of Application Security
Micro Focus Fortify Open source use is common and problematic.
Third party components make up a significant portion of many applications’ • Supports Java, .NET, JavaScript and Python
codebase, making Software Composition Analysis a “must-have” AppSec • Integrated results deliver one platform for remediation, reporting
capability. Fortify on Demand’s Software Composition Analysis, powered and analytics
by Sonatype, goes beyond a simple comparison of declared dependencies
• Examines fingerprints of 65M components for high accuracy—not just file
against the National Vulnerability Database (NVD). Using natural language
names and package manifests
processing, it dynamically monitors GitHub commits, open-source projects,
advisory websites, Google search alerts, Index, and several vulnerability sites. • Detects 70% more vulnerabilities than the NVD database alone
Additionally, a dedicated team of security experts regularly discovers new • 10M unique vulnerabilities to Sonatype
vulnerabilities and adds them to the proprietary knowledge base. Fortify on
Demand simplifies the onboarding and scanning process by combining static
and composition analysis into a single integration point, whether that’s in the Why Sonatype?
IDE or CI/CD pipeline. The comprehensive bill of materials, including security
vulnerabilities and license details, is delivered as a fully integrated experience 60% of the data that Sonatype ingests comes from public sources like the
for security professionals and developers alike. National Vulnerability Database. Sonatype corrects and curates that public
data augmenting 97% of it to make it more precise. This curation process
involves sophisticated ingestion tools, AI, and machine learning, along with a
Susceptibility Analysis team of 65 Data Security Researchers working nonstop.
microfocus.com | sonatype.com