Try our new research platform with insights from 80,000+ expert users

Veracode Fix Flaws

What effect, if any, has Veracode had on your organization’s ability to fix flaws? Please provide examples, if applicable.

reviewer2067186 - PeerSpot reviewer
Product Marketer at a media company with 1,001-5,000 employees
Worrying about fixing the flaws in an application is completely taken care of by Veracode, so we are able to focus more on creating new code and developing new applications. Veracode has been a great platform for that particular purpose.
View full review »
AK
LSA at a consultancy with 10,001+ employees
Veracode assists our clients in addressing flaws by simplifying the process. The security team can review the code, approve or reject it, and developers can utilize the reports to promptly rectify the flaws.
View full review »
SM
Data Research Analyst & Business Development at DIS Research
The main feature, and one of the most important, is the static code analysis. We are able to complete an analysis of the security flaws with this platform. It's very good and helping us find and fix flaws.
View full review »
reviewer2249226 - PeerSpot reviewer
Executive Assistant at a tech company with 51-200 employees
Veracode works very well overall, and our security has been greatly improved, significantly impacting our ability to fix flaws.
View full review »
Robert Hood - PeerSpot reviewer
Information Security Architect at a tech vendor with 5,001-10,000 employees
Veracode has been a great benefit because it allows developers to log in to their code and examine the specific vulnerabilities they were informed about. Typically, there is a description of why and how the vulnerability occurred, along with guidance on how to resolve it. Veracode significantly aids our organization in fixing flaws.
View full review »
OK
Sr. Development Manager at RWS Holdings PLC
Veracode has improved our product because we're gradually finding fewer and fewer issues through external security scanners or penetration testers. It plays an important role in the Azure quality assurance chain. We started using Veracode when it was supporting a 2017 standard. When the security standard changed to 2021, we received new issues.
View full review »
Oluseyi Osifalujo - PeerSpot reviewer
Executive Director at Precise Financial Systems Limited
Veracode has had a significant impact on our organization's ability to address flaws. The solution is capable of detecting issues and providing suggestions that assist us in rectifying problems within the code.
View full review »
Dipjyoti Roy - PeerSpot reviewer
Senior Devops Engineer at Thosmon Reuters
Ever since the implementation of Veracode, I have noticed that the processes for rectifying the issues in our pipelines have become much easier.
View full review »
Oscar Narvaez - PeerSpot reviewer
COE Head at a tech services company with 1,001-5,000 employees
Veracode has had an enormous impact on our ability to detect flaws. It's risky if we don't have the capacity to detect vulnerabilities in the earliest stage of development before the applications go into production.
View full review »
reviewer1699062 - PeerSpot reviewer
Sales Engineer at a computer software company with 51-200 employees
It has had a very good effect on our organization’s ability to fix flaws. We are developing a new feature, and Veracode will help to quickly fix any flaws.
View full review »
RB
Security Analyst at a insurance company with 10,001+ employees
Veracode has been fairly decent for fixing flaws. We have mainly been using it for SAST. For DAST, we have our AppScan from HCL, but Veracode is fairly decent for fixing flaws or trying to be proactive and ensuring all of our applications have been securely developed.
View full review »
Devid William - PeerSpot reviewer
Application Security Coordinator at Banco Votorantim
The security gate helps our developers learn how to fix vulnerabilities. The solution has also helped them save time in their efforts. It provides descriptions of how to fix certain items. It saves them from having to search on the internet for fixes.
View full review »
Sairam Bathini - PeerSpot reviewer
DevSecOps Engineer at Tata Consultancy
Because we integrated Veracode in the build tool, we get immediate reports. We can get the reports of Veracode while completing the build itself, which greatly impacts the delivery. We can review the report. We can report to our developer and make changes immediately if we have high or medium-vulnerability code injections, like SQL injection.
View full review »
SM
Security Analyst at a tech services company with 11-50 employees
Veracode introduced a new module named Veracode Fix, which automates the fixes for insecure software with AI-Generated secure code suggestions where the developer does not have to spend time searching and remediating the vulnerabilities. The developer does not have to spend time searching for vulnerabilities.
View full review »
PB
ML engineer at a consultancy with 10,001+ employees
The tool is great in terms of ensuring our code is clean, recommending best practices, and capturing the flaws in third-party components.
View full review »
Freddy Bang. - PeerSpot reviewer
Chief Technology Officer at ELEARNINGFORCE International ApS
It's bringing clarity to the flaws that we can mitigate, and that's the main purpose. We can have a brisk conversation about the flaws. Not all flaws need to be fixed because there might be other protection measures implemented.
View full review »
GR
System Engineer at a tech vendor with 10,001+ employees
Veracode has improved our organization's ability to fix flaws, and fixing vulnerabilities has sometimes required us to develop new features. This has actually helped us and made our applications better.
View full review »
Alice William - PeerSpot reviewer
Senior Web Developer at a insurance company with 1,001-5,000 employees
Veracode has been incorporated into our process, which helps us fix flaws. Whenever we develop external websites, we consider the code, the scanning, and everything else involved. This ensures that we are prepared and have enough time to receive the scan results and fix any issues. We have essentially incorporated this into the lifecycle of our project, which I believe is very valuable.
View full review »
reviewer2296401 - PeerSpot reviewer
CyberSec professional at a manufacturing company with 5,001-10,000 employees
Veracode's reporting function and executive summary help us emphasize the security of our business-critical products to our business, which also helps us get sponsorship from our management to fix flaws and move forward.
View full review »
Jan Pašek - PeerSpot reviewer
Tech Lead at a financial services firm with 10,001+ employees
Veracode has helped us fix flaws effectively. Our security teams enforce monitoring and fix deadlines for reported flaws. If a reported flaw cannot be accepted as a false positive, we must fix it promptly to maintain a high success rate.
View full review »
TR
Associate Software Engineer at a healthcare company with 201-500 employees
Veracode has significantly improved our speed in fixing software flaws. It has also transformed our approach to addressing issues. Previously, we spent considerable time investigating the root cause of errors in the code. Now, thanks to Veracode, we can devote more of our intellectual resources to directly fixing the system, which ultimately results in a more efficient product for our users.
View full review »
reviewer2333736 - PeerSpot reviewer
Cloud system engineer at a consultancy with 1-10 employees
Veracode has helped reduce our time to remediate security flaws.
View full review »
Evan Gertis - PeerSpot reviewer
Penetration Tester at a tech vendor with 51-200 employees
Veracode is highly efficient at fixing flaws. A single person can go through and do a penetration test after collecting the data from Veracode. Instead of telling developers where the issue is, they can show them in the code editor for the static analysis. They can assign tasks to the team using Jira, so developers almost never need to do that work. They actually almost never go back and fix any of these vulnerabilities. That's why I was my company's most hated and most loved man. I forced them to do it.
View full review »
reviewer2381340 - PeerSpot reviewer
Lead Consultant DevOps and Infrastructure at a tech vendor with 5,001-10,000 employees
Veracode assists our application team in fixing flaws by identifying issues and guiding the team toward resolving them.
View full review »
MS
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
Veracode helps us to fix flaws. They provide very good recommendations. It is very easy for a developer to fix the flaws. They provide a specific solution.
View full review »
David-Robertson - PeerSpot reviewer
Director Enterprise Architecture at Exeter Finance Corp.
It has helped us fix flaws. We know what's there, and there's generally a decent explanation for fixing each flaw. It's a quicker time to market. It's easy to figure out the problem and solve it we don't have exposed vulnerabilities in the market.
View full review »
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Veracode Fix has affected our time to remediate security flaws in cases where we've been able to use it correctly because the proposals were on point, and it's been great. We've seen that in the same sprint that we were developing the features, now those features are implemented without any technical security debt. What happened before was that we needed another sprint to solve those technical debts. So we haven't seen an increase in time, and the speed of development of the teams is better, and now the product is being delivered with less technical debt.
View full review »
reviewer2731785 - PeerSpot reviewer
Information Security Strategy at a insurance company with 10,001+ employees
Regarding remediation, based on my experience, the recommendation from Veracode on remediation is quite helpful. It gives valid reasoning, and the recommendation is fixed. The developers actually understand how to fix that. However, some of the recommendations, such as upgrading a certain library to version XYZ, sometimes don't go deeper because some of these libraries are not as simple as just changing the version to fix them. There are interdependencies with other third-party components. Sometimes, when the recommendation asks to upgrade the version to XYZ, when we actually upgrade it, there will be another issue with other things.
View full review »