{"id":"fd8dd0ac-827c-4a39-9ccc-d62c3e7ca130","engagementId":"65a8f365-9eaa-49ca-a243-65e64fe5ffeb","data":{"brief":{"id":"82fbe4c6-3520-4bca-86e7-9286d01beae1","name":"Cisco AppDynamics Vulnerability Disclosure Program","tagline":"Cisco AppDynamics is on a mission to help the world's most innovative companies live up to their boldest ambitions.","description":"\u003cp\u003eCisco AppDynamics offers tools and platforms that enable organizations to gain insights into the performance of their software applications in real-time. This includes features like application monitoring, end-user monitoring, business transaction monitoring, and infrastructure visibility. By providing detailed analytics and diagnostics, AppDynamics helps businesses identify and address performance issues, optimize resource utilization, and enhance the overall user experience.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and AppDynamics believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our targets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of AppDynamics not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to AppDynamics, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003eWe are primarily interested in the following vulnerabilities:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross Site Request Forgery (CSRF) (The severity will be considered on case by case basis)\u003c/li\u003e\n\u003cli\u003eServer Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eRemote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eSensitive information leakage (The severity will be considered on case by case basis)\u003c/li\u003e\n\u003cli\u003eAuthentication and Authorization\u003c/li\u003e\n\u003cli\u003eIn Direct Object Reference (IDOR)\u003c/li\u003e\n\u003cli\u003ePrivileged information belonging to other test users.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eUnder no circumstance you should contact Cisco AppDynamics support team or their customers.\u003c/li\u003e\n\u003cli\u003eDo not alter, disclose, or destroy any user data. Please always test on your own test users.\u003c/li\u003e\n\u003cli\u003eDo not exfiltrate any legitimate user data. Please always test on your own test users.\u003c/li\u003e\n\u003cli\u003eNo destructive testing (automated or otherwise). Please confirm with us if you are in doubt.\u003c/li\u003e\n\u003cli\u003eThird party software (library) effected with a known CVE.\u003c/li\u003e\n\u003cli\u003eAny third party applications that are not owned by AppDynamics.\u003c/li\u003e\n\u003cli\u003eMissing best practices such as HSTS, CSP, certificate pinning, cookie flags, etc...\u003c/li\u003e\n\u003cli\u003eReports from automated tools\u003c/li\u003e\n\u003cli\u003eNo social engineering of any kind (e.g. phishing, vishing, smishing)\u003c/li\u003e\n\u003cli\u003eNo brute forcing\u003c/li\u003e\n\u003cli\u003eSPF, DKIM, DMARC misconfiguration\u003c/li\u003e\n\u003cli\u003eD/DoS \u0026amp; any type of load testing\u003c/li\u003e\n\u003cli\u003eRate limiting issues\u003c/li\u003e\n\u003cli\u003eClick-jacking\u003c/li\u003e\n\u003cli\u003eContent spoofing\u003c/li\u003e\n\u003cli\u003eOpen redirect without clearly defining impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"a692d047-3ff0-4932-b8ed-689765162b79","name":"In Scope Targets","targets":[{"id":"7da9f3d7-d917-4d01-b1bf-ee54b3c1f0eb","uri":"https://www.appdynamics.com/","name":"*.appdynamics.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"50980b14-9e4b-4121-8080-8989fec602eb","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"7da9f3d7-d917-4d01-b1bf-ee54b3c1f0eb"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"7da9f3d7-d917-4d01-b1bf-ee54b3c1f0eb"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7da9f3d7-d917-4d01-b1bf-ee54b3c1f0eb"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"7da9f3d7-d917-4d01-b1bf-ee54b3c1f0eb"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"7da9f3d7-d917-4d01-b1bf-ee54b3c1f0eb"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003e\u003ca href=\"https://docs.appdynamics.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAppDynmaics Documentation\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"47ee6b1a-77c2-43d9-ae50-eb2c30f9c7b0","name":"Out of Scope Targets","targets":[{"id":"19f13041-ffb3-4360-a558-d54c227dadac","uri":"","name":"*.saas.appdynamics.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"045d4c9e-3def-404e-b614-07176137e4cc","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"86194f6d-1058-4ab2-ab63-d2dd4701e80c","uri":"","name":"*.corp.appdynamics.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3acd31c0-3d78-46f5-bd7c-10e7c2b9a8ce","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8ae80acc-0650-435a-9d9f-c7622e49db10","uri":"","name":"community.appdynamics.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"23a748d8-1626-4905-a007-02bd4a9c248c","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"2a321274-3444-44c9-978f-3464ee78318e","uri":"","name":"community.splunk.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b9ed2cbb-8247-4332-a956-ec30de34f05a","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThe following targets are explicitly out of scope. \u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"65a8f365-9eaa-49ca-a243-65e64fe5ffeb","code":"appdynamics-vdp","state":"in_progress","endsAt":null,"bountyId":"1db92788-dc5e-42de-b202-dba727435e92","startsAt":"2024-01-16T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/8059/14b9/f82579e2/47b7146ae7653a799e20b28b8b24de4e_1688134380980.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-01-16T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/appdynamics-vdp","changelogs":"/engagements/appdynamics-vdp/changelog","submissions":null,"announcements":"/engagements/appdynamics-vdp/announcements","hallOfFame":"/engagements/appdynamics-vdp/hall_of_fames","crowdstream":"/engagements/appdynamics-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/appdynamics-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=appdynamics-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/appdynamics-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/appdynamics-vdp/changelog","publishedAt":"2025-03-07T21:27:49.087Z","engagementChangelogUrl":"/engagements/appdynamics-vdp/changelog/fd8dd0ac-827c-4a39-9ccc-d62c3e7ca130","createUserFeedbacksUrl":"/engagements/appdynamics-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/appdynamics-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}