Vulnerability disclosure and reporting

Vulnerability disclosure and reporting

Introduction

This reporting tool allows our internal teams to make us aware of any security issues impacting our products or services.

If you have identified a security vulnerability, suspected exploit activity, or a security weakness affecting one of our products, services, or systems, please notify our Vulnerability Management team using the details below who will respond as soon as possible.

Contact the Vulnerability Management Team

Our objective is to assess reports promptly, understand potential risk, and coordinate appropriate adjustments to help protect our customers, users, and services to our best ability.

Before you submit

Please provide as much information as possible to help us validate and assess the reported vulnerability. Reports containing detailed information are more likely to be assessed and investigated quickly.

Minimum information required

Please include the following:

  • Product name, version, or identifier (if known)
  • Product location or URL
  • Initial severity assessment (if known)
  • Link(s) to supporting evidence, alert, advisory, report, proof of concept, or screenshots.

Information to include in your submission

1. Product Information

  • Product name
  • Version or build affected
  • Product type (e.g., software, SaaS application, cloud service, IoT device, firmware, mobile application)
  • Unique identifiers (SKU, model number, service name, asset ID, etc.)

2. Deployment Context

Please identify where the affected product is deployed:

  • On-premises
  • SaaS / Cloud-hosted
  • Firmware or hardware device
  • Mobile application
  • Other deployment model

3. Scope of Impact

Please describe:

  • Which components, modules, services, or features are affected
  • Whether the vulnerability impacts:
    • All versions
    • Specific versions only
    • Specific product configurations
    • Particular environments or deployment models

4. Nature of the Vulnerability

Please provide:

  • Vulnerability type (if known)
    • Authentication bypass
    • Remote code execution
    • Privilege escalation
    • SQL injection
    • Cross-site scripting (XSS)
    • Information disclosure
    • Denial of service
    • Misconfiguration
    • Other
  • High-level description of the issue

5. Nature of the Exploit

Where known, please describe:

  • How the vulnerability is being exploited
  • Whether exploitation is:
    • Ongoing
    • Suspected
    • Confirmed
  • Whether attacks appear to be:
    • Targeted
    • Opportunistic
    • Widespread

6. Supporting Evidence

Please include any relevant evidence such as:

  • Security advisories
  • Threat intelligence reports
  • Proof-of-concept code
  • Screenshots
  • Log extracts
  • Network captures
  • Vendor notifications
  • Links to publicly available references (e.g., CVE, NVD, CISA, vendor advisories)

Example submission template

  1. Product Name:
  2. Version/Build:
  3. Product Type:
  4. Product Location:
  5. Deployment Context:
  6. Affected Components:
  7. Vulnerability Type:
  8. Initial Severity:
  9. Description:
  10. Known Exploitation Activity:
  11. Affected Versions/Configurations:
  12. Evidence/References:
  13. Reporter Contact Details:

The Vulnerability Management team will assess the information provided in accordance with our vulnerability assessment and risk management processes to demonstrate our commitment and acknowledgement to reviewing all reports. 

Thank you for helping us and together we can help maintain a secure environment. 

Contact the Vulnerability Management Team