Oracle Platforms · Vulnerability Disclosure

Oracle Platforms Vulnerability Disclosure

Vulnerability disclosure

Oracle Platforms runs a coordinated vulnerability disclosure program on Hackerone.

AnalyticsCloud ComputingDatabaseEnterprise SoftwareInfrastructure-as-a-ServiceIntegrationMachine-LearningPlatform-as-a-ServiceSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/
  (HTTP 200 after a 301 from .../reporting.html) and
  https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ (HTTP 200)
provider: Oracle Platforms
providerId: oracle-platforms
program:
  published: true
  name: Reporting Security Vulnerabilities to Oracle
  url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/
  policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/
  contact: secalert_us@oracle.com
  encryption:
    supported: true
    method: PGP
    note: >-
      Oracle publishes a PGP key and asks reporters to encrypt reports, proof-of-concept
      details, logs and attachments before transmission.
  bug_bounty: false
  bug_bounty_note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. Oracle runs a coordinated
    disclosure program with researcher credit rather than a paid bounty.
  remediation_channel:
    name: Critical Patch Update / Security Alert
    description: >-
      Oracle's stated policy is to credit the reporting researcher in the applicable
      Critical Patch Update, Critical Security Patch Update, or Security Alert advisory
      once a fix ships.
  researcher_requirements:
    - Follow responsible disclosure practices
    - Do not publish the vulnerability before Oracle ships a fix
security_txt:
  served: false
  note: >-
    Oracle serves NO RFC 9116 /.well-known/security.txt on any host probed
    (www.oracle.com 302s to root then 403s at the edge; docs.oracle.com and
    cloud.oracle.com return a genuine 404). The disclosure program is real and
    well-documented — it is simply not machine-discoverable at the standard path. See
    well-known/oracle-platforms-well-known.yml for the full probe record.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/oracle-platforms-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.