— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Veeam.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": false,
"average_time_to_bounty_awarded": null,
"average_time_to_first_program_response": 19,
"average_time_to_report_resolved": 2763,
"handle": "veeam",
"id": 0,
"managed_program": true,
"name": "Veeam",
"offers_bounties": false,
"offers_swag": false,
"response_efficiency_percentage": 73,
"submission_state": "open",
"url": "https://hackerone.com/veeam",
"website": "http://www.veeam.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.kasten.io",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.securiti.ai",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "***The following are IN scope for this asset:***\n\nCross-Site Scripting (XSS)\nOpen redirect\nCross-site Request Forgery (CSRF)\nCommand/File/URL inclusion\nAuthentication issues\nCode execution\nCode or database injections\n\n\n***The following are OUT of scope for this asset:***\n\nAccount/email enumerations\nDenial of Service (DoS)\nAttacks that could harm the reliability/integrity of our business\nSpam attacks\nClickjacking on pages without authentication and/or sensitive state changes\nMixed content warnings\nLack of DNSSEC\nContent spoofing / text injection\nTiming attacks\nSocial engineering\nPhishing\nInsecure cookies for non-sensitive cookies or 3rd party cookies\nVulnerabilities requiring exceedingly unlikely user interaction\nExploits that require physical access to a user's machine",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.veeam.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.veeamgov.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Corporate Infrastructure",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Vulnerabilities in any Veeam owned/managed corporate infrastructure.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Product Vulnerabilities",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Security vulnerabilities that are identified in currently supported Veeam products.",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "Customer Support Request Forms",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Customer support request forms (i.e. - Veeam Customer Portal Cases and Case Escalation Forms) are not in scope for this program.\n",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "Virtual Chat Assistants",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Virtual chat assistants on our websites are provided by an out of scope 3rd party and are not in scope for this program.",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}Corporate Infrastructure· criticalProduct Vulnerabilities· criticalCustomer Support Request FormsotherVirtual Chat Assistantsother