Oracle Hospitality · Vulnerability Disclosure

Oracle Hospitality Vulnerability Disclosure

Vulnerability disclosure

Oracle Hospitality publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

TravelUnited StatesHospitalityHotelsProperty ManagementDistributionChannel ManagementBookingReservationsPoint-of-Sale
Program:

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
secalert_us@oracle.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-28'
method: searched
probe: true
source: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
scope: >-
  Oracle Hospitality has no product-specific disclosure programme; it inherits Oracle Corporation's
  company-wide vulnerability handling policy, which is also the policy declared on the public
  oracle/hospitality-api-docs specification repository.
policy:
- https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
- https://www.oracle.com/corporate/security-practices/assurance/vulnerability/
- https://github.com/oracle/hospitality-api-docs/blob/main/SECURITY.md
contact:
- secalert_us@oracle.com
encryption_key: https://www.oracle.com/security-alerts/encryptionkey.html
security_txt:
  published: false
  probed:
  - url: https://www.oracle.com/.well-known/security.txt
    status: 403
  - url: https://docs.oracle.com/.well-known/security.txt
    status: 404
bug_bounty:
  published: false
  note: >-
    Oracle does not operate a public bug bounty. Researchers are credited in the applicable Critical Patch
    Update, Critical Security Patch Update or Security Alert advisory when a fix ships.
reporting_channels:
- audience: Oracle customers and partners
  channel: Designated support mechanism (My Oracle Support or SuiteSupport) service request
- audience: Everyone else
  channel: Email secalert_us@oracle.com, PGP encryption encouraged
coordinated_disclosure_terms:
- Do not publish the vulnerability before Oracle releases a fix.
- Do not disclose exact details of the issue, such as exploits or proof-of-concept code.
- Coordinate disclosure with Oracle to allow sufficient time for remediation.
- Oracle does not credit employees or contractors of Oracle and its subsidiaries.
patch_cadence:
  programme: Oracle Critical Patch Update
  advisories: https://www.oracle.com/security-alerts/
evidence:
- source: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
  kind: disclosure-policy-page
  status: 200
  quote: >-
    If you are not an Oracle customer or partner, please email secalert_us@oracle.com with your discovery.
- source: https://github.com/oracle/hospitality-api-docs/blob/main/SECURITY.md
  kind: repository-security-policy
  status: 200
  quote: >-
    Please do NOT raise a GitHub Issue to report a security vulnerability. If you believe you have found a
    security vulnerability, please submit a report to secalert_us@oracle.com preferably with a proof of
    concept.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oracle-hospitality-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.