Oracle Siebel · Vulnerability Disclosure

Oracle Siebel Vulnerability Disclosure

Vulnerability disclosure

Oracle Siebel runs a coordinated vulnerability disclosure program on Hackerone.

CRMCustomer ManagementEnterprise SoftwareMarketing AutomationOracleSales AutomationService Automation
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: >-
  https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
  (HTTP 200),
  https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure.html
  (HTTP 200), https://www.oracle.com/security-alerts/ (HTTP 200)
provider: Oracle Siebel
providerId: oracle-siebel
published: true
program_type: coordinated-disclosure
bug_bounty: false
summary: >-
  Oracle operates a corporate coordinated-disclosure programme that covers every
  Oracle product, Siebel CRM included. There is no Siebel-specific policy and no
  paid bug bounty: Oracle explicitly states it does not distribute exploit or
  proof-of-concept code and does not give advance notification to individual
  customers. Fixes ship on the quarterly Critical Patch Update cycle, with
  out-of-band Security Alerts for severe issues.
policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure.html
reporting_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html
advisories_url: https://www.oracle.com/security-alerts/
security_txt: false
security_txt_note: >-
  Oracle serves no /.well-known/security.txt. www.oracle.com returns HTTP 403 to
  an unauthenticated request for that path (edge challenge) and docs.oracle.com
  returns 404 — see well-known/oracle-siebel-well-known.yml.
contacts:
  - channel: email
    value: secalert_us@oracle.com
    audience: >-
      Researchers who are not Oracle customers or partners. Oracle asks that
      sensitive material be encrypted with its published public PGP key.
  - channel: my-oracle-support
    value: https://support.oracle.com/
    audience: >-
      Oracle customers and partners, who are asked to raise a service request
      rather than email.
disclosure_terms:
  - >-
    Researchers must follow responsible disclosure to be eligible for credit:
    do not publish before Oracle releases a fix, and do not disclose exact
    details such as exploits.
  - >-
    Oracle provides no information about vulnerability specifics beyond the
    Critical Patch Update or Security Alert advisory, prerelease note,
    preinstallation notes, readme files and FAQs.
  - Oracle does not provide advance notification to individual customers.
  - Oracle does not distribute exploit code or proof-of-concept code.
remediation_cadence:
  program: Critical Patch Update
  frequency: quarterly
  out_of_band: Security Alerts
  url: https://www.oracle.com/security-alerts/
third_party_listings:
  - platform: HackerOne
    url: https://hackerone.com/oracle
    http_status: 200
    type: response-policy-directory-entry
    bounty: false
    note: >-
      A HackerOne directory entry exists for Oracle. It is a response-policy
      listing, not a paid bounty programme; Oracle's own policy pages remain the
      authoritative route and direct reporters to secalert_us@oracle.com or My
      Oracle Support.
scope_note: >-
  This is a parent-brand programme. Siebel CRM is an Oracle product and is
  covered by Oracle's corporate vulnerability handling; Oracle publishes no
  Siebel-specific disclosure policy.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com