Oracle Siebel · Vulnerability Disclosure
Oracle Siebel Vulnerability Disclosure
Vulnerability disclosure
Oracle Siebel runs a coordinated vulnerability disclosure program on Hackerone.
CRMCustomer ManagementEnterprise SoftwareMarketing AutomationOracleSales AutomationService Automation
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-13'
method: searched
source: >-
https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
(HTTP 200),
https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure.html
(HTTP 200), https://www.oracle.com/security-alerts/ (HTTP 200)
provider: Oracle Siebel
providerId: oracle-siebel
published: true
program_type: coordinated-disclosure
bug_bounty: false
summary: >-
Oracle operates a corporate coordinated-disclosure programme that covers every
Oracle product, Siebel CRM included. There is no Siebel-specific policy and no
paid bug bounty: Oracle explicitly states it does not distribute exploit or
proof-of-concept code and does not give advance notification to individual
customers. Fixes ship on the quarterly Critical Patch Update cycle, with
out-of-band Security Alerts for severe issues.
policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure.html
reporting_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
advisories_url: https://www.oracle.com/security-alerts/
security_txt: false
security_txt_note: >-
Oracle serves no /.well-known/security.txt. www.oracle.com returns HTTP 403 to
an unauthenticated request for that path (edge challenge) and docs.oracle.com
returns 404 — see well-known/oracle-siebel-well-known.yml.
contacts:
- channel: email
value: secalert_us@oracle.com
audience: >-
Researchers who are not Oracle customers or partners. Oracle asks that
sensitive material be encrypted with its published public PGP key.
- channel: my-oracle-support
value: https://support.oracle.com/
audience: >-
Oracle customers and partners, who are asked to raise a service request
rather than email.
disclosure_terms:
- >-
Researchers must follow responsible disclosure to be eligible for credit:
do not publish before Oracle releases a fix, and do not disclose exact
details such as exploits.
- >-
Oracle provides no information about vulnerability specifics beyond the
Critical Patch Update or Security Alert advisory, prerelease note,
preinstallation notes, readme files and FAQs.
- Oracle does not provide advance notification to individual customers.
- Oracle does not distribute exploit code or proof-of-concept code.
remediation_cadence:
program: Critical Patch Update
frequency: quarterly
out_of_band: Security Alerts
url: https://www.oracle.com/security-alerts/
third_party_listings:
- platform: HackerOne
url: https://hackerone.com/oracle
http_status: 200
type: response-policy-directory-entry
bounty: false
note: >-
A HackerOne directory entry exists for Oracle. It is a response-policy
listing, not a paid bounty programme; Oracle's own policy pages remain the
authoritative route and direct reporters to secalert_us@oracle.com or My
Oracle Support.
scope_note: >-
This is a parent-brand programme. Siebel CRM is an Oracle product and is
covered by Oracle's corporate vulnerability handling; Oracle publishes no
Siebel-specific disclosure policy.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com