{"id":"94ae44bf-701a-47f9-b1cc-052c0b8db3d5","engagementId":"54eaced8-20d0-4724-8fe4-eb3873414eb5","data":{"brief":{"id":"afd10cc4-018c-4ebe-b3ba-3b5992bd358a","name":"FIS","tagline":"Advancing the ways the world pays, banks and invests.","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eNo technology is perfect, and as the threat landscape evolves, it becomes increasingly important for organizations to secure their assets. FIS believes that working with skilled security researchers across the globe is an integral part in keeping our businesses and customers safe. \u003c/p\u003e\n\n\u003cp\u003eBy researchers proactively identifying vulnerabilities in FIS application environments, it will aid in enhancing our overall security posture and enable us to better protect our customers and their data. We are excited for you to participate as a security researcher and help FIS become more secure. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003ePolicy\u003c/h2\u003e\n\n\u003cp\u003eFIS looks forward to working with the security community and appreciates the time and effort researchers put towards our program. FIS will make a best effort to respond to incoming reports within 5 business days and make a bounty determination after validating a legitimate security issue within 10 business days. We will try to keep researchers informed about our progress throughout the process.\u003c/p\u003e\n\n\u003cp\u003eFIS has defined a list of general program rules, as well as rules regarding specific circumstances. Researchers must adhere to the stated rules and are encouraged to review all the rules presented in this brief. Any rule violations could potentially deem a submission ineligible for reward.\u003c/p\u003e\n\n\u003cp\u003eWhile scope is covered in more detail in the program rules, it's worth noting that FIS is a large service provider. There are many applications that we provide hosting or support services for, but we don't always own those assets. Depending on the specific situation, submissions may be deemed out of scope for this reason.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, when FIS publicly announces we are divesting an existing business asset, we will no longer accept any Bug Bounty submissions on the asset. If you have questions regarding scope, feel free to contact \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e to confirm asset ownership.\u003c/p\u003e\n\n\u003cp\u003eOur program evolves over time, so researchers are also encouraged to periodically review this program page for any rule changes. Researchers should also visit the \u003cstrong\u003e\u003ca href=\"https://bugcrowd.com/fis/updates\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAnnouncements\u003c/a\u003e\u003c/strong\u003e page for program notifications.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003eImportant Announcements\u003c/h2\u003e\n\n\u003cp\u003eThis section highlights key program announcements for your reference. This section will update periodically as program conditions change.\u003cbr\u003e\n \u003cbr\u003e\n1) Do not submit any reports containing Personally Identifiable Information (PII). Some examples of PII include the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSocial Security Number\u003c/li\u003e\n\u003cli\u003eName\u003c/li\u003e\n\u003cli\u003eAddress\u003c/li\u003e\n\u003cli\u003eEmail address\u003c/li\u003e\n\u003cli\u003ePhone number\u003c/li\u003e\n\u003cli\u003eEtc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003eScreenshots may be included in submissions, but any PII data must be redacted. Any report with PII will be closed and not paid out.\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cp\u003e2) Targets that achieve $50,000.00 in rewards within a 30-day period are still subject to scope removal for internal evaluation. However, any valid reports submitted before scope removal will still be eligible for payout. If you have any questions, please reach out to \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cp\u003e3) There are multiple program rules regarding credentials, and we encourage researchers to review these rules prior to submitting reports to the program. For example, we do not accept reports where credentials were guessed/brute forced, and we do not accept reports for leaked credentials (e.g., Github, dark web, etc.).\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cp\u003e4) Third-Party / Vendor-Dependent Vulnerabilities\u003c/p\u003e\n\n\u003cp\u003eWhen a vulnerability meets the following criteria, the report may be subject to non-payment, or a reduced reward (up to 10% of the standard payout):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe vulnerability exists within vendor-owned code or infrastructure\u003c/li\u003e\n\u003cli\u003eThe vulnerability is not the result of FIS running an outdated or unsupported version\u003c/li\u003e\n\u003cli\u003eThe vulnerability requires vendor engagement for remediation\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cp\u003e5) Write Actions in Production Environments\u003c/p\u003e\n\n\u003cp\u003eResearchers must not perform write actions or make any changes in production environments, unless the write actions or changes are against records created by the researcher for testing purposes.\u003c/p\u003e\n\n\u003cp\u003eExamples include (but are not limited to):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreating, modifying, or deleting data\u003c/li\u003e\n\u003cli\u003eChanging account settings\u003c/li\u003e\n\u003cli\u003eTriggering state changes\u003c/li\u003e\n\u003cli\u003eUploading executable or active content\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you think you've discovered a vulnerability that enables write access or modification capabilities, and you're unable to create your own record to test against, pause testing and reach out to \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cp\u003e6) File Upload Testing\u003c/p\u003e\n\n\u003cp\u003eWhen evaluating file upload functionality, avoid excessive upload attempts. Once a single, successful proof of concept (PoC) is achieved, discontinue further uploads, and submit your report. A clear and concise PoC is sufficient for validation.\u003c/p\u003e\n\n\u003cp\u003eFile uploads beyond what's necessary may introduce avoidable risk and could affect reward eligibility. Additionally, if you upload/write a file to a system, include your Bugcrowd username in the file name (e.g., tester123_poc.txt). This will assist in deconflicting logs and traffic.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003ch3\u003eTraffic Identification\u003c/h3\u003e\n\n\u003cp\u003eIn an effort to assist in deconflicting logs and traffic, we are heavily enforcing a new rule on our program. Effective immediately, please include the following custom header in any testing activity against FIS assets:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;username\u0026gt;\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\"Testing activity\" includes any requests sent to an FIS asset, be it automated or manual testing. The ability to deconflict Bug Bounty traffic will assist us when we are reviewing reports and activity. It will also minimize the potential for business impact.\u003c/p\u003e\n\n\u003cp\u003eFailure to include the \"X-Bug-Bounty\" header, or failure to set the header in the specified format, will result in payment being reduced by 75%. Repeat failures to adhere to this rule may result in non-payment.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch3\u003eRemote Code Execution (RCE) Submissions\u003c/h3\u003e\n\n\u003cp\u003eIf you have identified and exploited a Remote Code Execution vulnerability, you must submit the report for this finding within \u003cstrong\u003ethree hours\u003c/strong\u003e of exploitation. Additionally, only \u003cstrong\u003enon-intrusive\u003c/strong\u003e demonstrations of impact will be allowed, unless we have granted explicit permission to do otherwise.\u003c/p\u003e\n\n\u003cp\u003eNon-intrusive demonstrations of impact are as follows:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOutbound DNS request (e.g., nslookup [yourDomain])\u003c/li\u003e\n\u003cli\u003eDirectory listing (e.g., dir, ls, pwd)\u003c/li\u003e\n\u003cli\u003eEchoing the hostname (e.g., hostname)\u003c/li\u003e\n\u003cli\u003eEchoing the current user (e.g., whoami)\u003c/li\u003e\n\u003cli\u003eEchoing some text (e.g., echo BugBounty)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eFailure to adhere to these rules will result in a reduced payout of 75%, or potentially no payment for the submission. If you have any questions, please reach out to \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch3\u003eAccount Take Over (ATO) Submissions\u003c/h3\u003e\n\n\u003cp\u003eIf you have identified a potential Account Take Over vulnerability that would affect FIS customer or client accounts, \u003cstrong\u003edo not\u003c/strong\u003e proceed in taking over the account. Please reach out to \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e and request instructions for how to proceed. Failure to do so may result in the submission not being accepted, as we cannot allow disruptions to our customers and clients.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch3\u003eAutomated Tooling Requests\u003c/h3\u003e\n\n\u003cp\u003eAny automated tooling requests must be capped to a maximum of 5 requests per second. Researchers must not exceed the 5 requests per second limit at any time. Failure to do so may result in submissions not being accepted, as we cannot allow disruptions to our customers and clients.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch3\u003eAdditional Rules\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSee the \"Application Access\" section for rules on authenticated testing.\u003c/li\u003e\n\u003cli\u003eDo not publicly disclose a bug.\u003c/li\u003e\n\u003cli\u003eDo not perform any testing that causes degradation to FIS or customer assets (e.g., Denial of Service (DoS), heavy automated scanning, etc.).\u003c/li\u003e\n\u003cli\u003eImpacting our customers or customer data without our explicit approval is strictly prohibited.\u003c/li\u003e\n\u003cli\u003eResearchers cannot utilize valid end-user credentials for any purpose.\n\n\u003cul\u003e\n\u003cli\u003eThis is for legal and privacy compliance.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eNo brute forcing/guessing log in credentials.\u003c/li\u003e\n\u003cli\u003eData exfiltration is strictly prohibited.\u003c/li\u003e\n\u003cli\u003eResearchers cannot purchase a service or request a product demo and then utilize any provisioned credentials for testing purposes.\u003c/li\u003e\n\u003cli\u003eWe reserve the right not to pay bounties for security bugs found in sites that are not on a product, service, or piece of infrastructure owned, operated, or maintained by FIS or any FIS-acquired entity.\n\n\u003cul\u003e\n\u003cli\u003eFor example, assets that are 3rd party hosted, 3rd party owned, or 3rd party supported may be considered out of scope.\u003c/li\u003e\n\u003cli\u003eIf you have questions regarding scope, please contact \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWe reserve the right not to pay bounties for security bugs in or caused by additional third-party software (e.g., binary plugins, extensions, etc.).\n\n\u003cul\u003e\n\u003cli\u003eIf you have questions regarding scope, please contact \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities are only eligible if they have not been previously discovered by our normal scanning tools, penetration tests, or other processes and sources.\u003c/li\u003e\n\u003cli\u003eVulnerabilities must be exploitable directly from the internet.\u003c/li\u003e\n\u003cli\u003eVulnerabilities eligible for payout must be unauthenticated or discovered with default or self-registered credentials.\u003c/li\u003e\n\u003cli\u003eIf you identify and utilize default credentials for an application, you must also indicate where the default credentials were discovered (e.g., vendor documentation, config file, etc.).\u003c/li\u003e\n\u003cli\u003eFIS/WP Employees and contractors may not participate or collaborate on any FIS managed bug bounty program.\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities that use credentials obtained by means other than intended self-registration will be subject to a reduced payout.\u003c/li\u003e\n\u003cli\u003eAny proof of concepts should not include images or statements that could cause reputational damage to FIS or its customers (e.g., brand damage or tagging on takeover pages).\u003c/li\u003e\n\u003cli\u003eMultiple instances of the same application and vulnerability combination are only eligible for a single payout.\u003c/li\u003e\n\u003cli\u003eIf you have identified a single vulnerability affecting multiple endpoints that can be addressed with a single fix/remediation, please submit a single finding listing all those endpoints.\n\n\u003cul\u003e\n\u003cli\u003eWe will individually review each endpoint and assess the eligible payout.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eIn cases where there is shared code between multiple assets, bounties will only be paid for one instance of a vulnerability, as only one fix will need to be implemented in the shared code base.\u003c/li\u003e\n\u003cli\u003eThe following actions are forbidden on internal FIS systems:\n\n\u003cul\u003e\n\u003cli\u003eInternal pivoting\u003c/li\u003e\n\u003cli\u003eScanning\u003c/li\u003e\n\u003cli\u003eVulnerability exploitation\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eIf you have identified a Remote Code Execution (RCE) or similar vulnerability, please feel free to contact \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e and determine the best way to demonstrate a safe proof of concept.\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g., phishing, vishing, smishing, etc.) is strictly prohibited.\u003c/li\u003e\n\u003cli\u003ePlease provide detailed reports with reproducible steps.\n\n\u003cul\u003e\n\u003cli\u003eReports without sufficient details to reproduce the issue will not be eligible for a reward.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAny potential or theoretical vulnerabilities that are mentioned without demonstration of exploitability will not be paid out.\n\n\u003cul\u003e\n\u003cli\u003eExploitations must remain within the guidelines of our scope and program rules.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSubmit one vulnerability per report, unless you can chain the vulnerabilities.\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n\n\u003cul\u003e\n\u003cli\u003ePost-authentication vulnerabilities are much more likely to have internal duplicates and single core fixes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePriority and payment are based on the environment (e.g., production, UAT, development, etc.), the vulnerability, and an internal analysis of the asset and relevant data.\u003c/li\u003e\n\u003cli\u003eAny report leveraging archive engines (e.g., urlscan.io, web.archive.org, or similar sites) must demonstrate an in scope finding.\n\n\u003cul\u003e\n\u003cli\u003eFor example - utilizing leaked tokens, API keys, or application data to demonstrate read/write access to an application.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWhen FIS acquires a company, that company’s assets are not automatically in scope for the FIS Bug Bounty program.\n\n\u003cul\u003e\n\u003cli\u003eThose assets will not be considered in scope until we send an announcement indicating that they are now in scope.\u003c/li\u003e\n\u003cli\u003eReports submitted against those assets prior to the announcement will not be honored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003eSensitive Data\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eOnce sensitive data (e.g., PII, financial information, etc.) is identified, immediately halt your activity, purge related data from your system, and report the finding to FIS.\u003c/li\u003e\n\u003cli\u003eIf PII is discovered, indicate the type of PII in the report (e.g., Social Security Number, name, address, etc.).\u003c/li\u003e\n\u003cli\u003eDo not submit any reports with PII. \n\n\u003cul\u003e\n\u003cli\u003eAny report with PII will be closed and not paid out. \u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003eOut of scope vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider the following:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e The attack scenario.\u003c/li\u003e\n\u003cli\u003e The exploitation potential of the vulnerability.\u003c/li\u003e\n\u003cli\u003e The security impact of the vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cp\u003eThe following issues are considered out of scope and are not included within our program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMobile application vulnerabilities\u003c/li\u003e\n\u003cli\u003eReflected and DOM Cross-Site Scripting (XSS).\u003c/li\u003e\n\u003cli\u003eSocial engineering-based attacks (e.g., getting a user to click an attacker-controlled link).\u003c/li\u003e\n\u003cli\u003eSubdomain Takeovers.\u003c/li\u003e\n\u003cli\u003eDenial of Service, Rate Limiting, or Spamming issues (e.g., layer 7 DOS attacks, Slowloris, etc.).\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF).\u003c/li\u003e\n\u003cli\u003eMan in the Middle (MITM) attacks.\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical access to a user's device.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that require privileged access to a victim's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working proof of concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection.\u003c/li\u003e\n\u003cli\u003eContent spoofing or text injection (e.g., HTML or CSS injection).\u003c/li\u003e\n\u003cli\u003eIFRAME injection.\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans without accompanying demonstration of exploitability.\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure without accompanying demonstration of exploitability.\u003c/li\u003e\n\u003cli\u003eUse of a known-vulnerable library without evidence of exploitability.\u003c/li\u003e\n\u003cli\u003eOpen redirects.\u003c/li\u003e\n\u003cli\u003eSender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), or Domain-based Message Authentication Reporting and Conformance (DMARC) record issues.\u003c/li\u003e\n\u003cli\u003eMissing best practices.\u003c/li\u003e\n\u003cli\u003eInsecure SSL or TLS issues (e.g., ciphers, certificates, etc.).\u003c/li\u003e\n\u003cli\u003eUser existence or enumeration vulnerabilities.\u003c/li\u003e\n\u003cli\u003ePassword or account recovery policies (e.g., reset link expiration, password complexity, etc.).\u003c/li\u003e\n\u003cli\u003eAny physical attempts against FIS property or data centers.\u003c/li\u003e\n\u003cli\u003eMissing or misconfigured security headers (e.g., HTTP Strict-Transport-Security (HSTS), Content Security Policy (CSP), etc.) that do not lead directly to a vulnerability.\u003c/li\u003e\n\u003cli\u003ePresence of the “autocomplete” attribute on web forms.\u003c/li\u003e\n\u003cli\u003eHost header injections unless you can show how they can lead to stealing user data.\u003c/li\u003e\n\u003cli\u003eInsecure cookie settings for non-sensitive cookies.\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting users of outdated browsers or platforms.\u003c/li\u003e\n\u003cli\u003eIssues related to software or protocols not under FIS control.\u003c/li\u003e\n\u003cli\u003eIssues related to descriptive or verbose error messages.\u003c/li\u003e\n\u003cli\u003eVulnerabilities in third party applications that make use of an FIS API.\u003c/li\u003e\n\u003cli\u003eRecently disclosed zero-day vulnerabilities.\n\n\u003cul\u003e\n\u003cli\u003ePlease see the announcement regarding this.\u003c/li\u003e\n\u003cli\u003eWe will reward 10% of the payout within the first 14 days from the vendor releasing a patch, or the full amount after 14 days.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFlash-based vulnerabilities.\u003c/li\u003e\n\u003cli\u003eALL Github and Postman leaks.\u003c/li\u003e\n\u003cli\u003eAny kind of credentials leak.\u003c/li\u003e\n\u003cli\u003eAny submissions from urlscan.io, web.archive.org, or similar sites that merely shows information being cached (e.g., name or email from a form submission).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003eAny reports of vulnerabilities on domains in the \"\u003cstrong\u003eOut of Scope\u003c/strong\u003e\" list will be closed as N/A and will not qualify for a bounty.\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003ePublic Disclosure\u003c/h2\u003e\n\n\u003cp\u003ePlease do not discuss this program or any vulnerabilities (including resolved vulnerabilities) outside of the program without express consent from FIS. FIS strictly prohibits the discussion or disclosure of reports outside of the researcher that submitted the report, BugCrowd, or FIS.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003eInternal Duplicates\u003c/h2\u003e\n\n\u003cp\u003eDue to alternate means of vulnerability discovery (e.g., scanning, penetration tests, etc.), there will be some vulnerabilities that we're already aware of. We will work to be as transparent as possible should you file a duplicate to an internal issue.\u003c/p\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch2\u003eApplication Access\u003c/h2\u003e\n\n\u003cp\u003ePlease review the following points regarding application access:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFIS does not provision accounts for testing.\u003c/li\u003e\n\u003cli\u003eFIS does not condone the sharing of credentials.\u003c/li\u003e\n\u003cli\u003eFIS reserves the right to not pay bounties on reports found to be using valid end-user credentials.\u003c/li\u003e\n\u003cli\u003eResearchers are forbidden from soliciting credentials from FIS clients, including the customers of FIS clients.\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities that use credentials obtained by means other than self-registration will be subject to a reduced payout.\u003c/li\u003e\n\u003cli\u003eWherever possible, researchers should include 'Bugcrowd Bug Bounty' in plaintext to allow our SOC team to deconflict logging data.\u003c/li\u003e\n\u003cli\u003eAccess from Digital Ocean IPs may be restricted.\u003c/li\u003e\n\u003cli\u003eAccess from non-US IPs may be restricted. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e \u003c/p\u003e\n\n\u003ch3\u003eNote:\u003c/h3\u003e\n\n\u003cp\u003ePlease ensure that any FIS site you're testing actually belongs to FIS. Reviewing SSL certs, whois records, and DNS entries are potential ways to determine ownership. Please do not rely on Wikipedia to confirm what companies FIS has acquired. If you have any concerns about whether or not an asset belongs to FIS, please reach out to \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003eFIS provides a wide range of financial products and services, including web development, application hosting, and DNS services. As such, there will be a number of sites where FIS only owns a section of them. There will also be situations where we host the site and own the domain but are not contractually responsible for the security of that site.\u003c/p\u003e\n\n\u003cp\u003eWe strive to be as transparent as possible with our bug bounty community. If a report comes in that meets this criteria, we will work with the researcher to determine the best path forward, which may include engaging the customer or client.\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy.\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls.\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy.\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003cstrong\u003e\u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e\u003c/strong\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1f8444eb-515d-42f4-b7be-0110be0d0199","name":"In scope","targets":[{"id":"c2def1e6-5322-4140-a75c-866b21c9cd4e","uri":"","name":"Any FIS asset is in scope","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bb357f4c-3df4-49f1-9d15-0235d78adf33","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"da306d71-3cd3-485d-a199-1f9412939e89","p1MaxCents":2000000,"p1MinCents":1000000,"p2MaxCents":1000000,"p2MinCents":250000,"p3MaxCents":250000,"p3MinCents":20000,"p4MaxCents":20000,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":10000,"max":20000},"2":{"min":2500,"max":10000},"3":{"min":200,"max":2500},"4":{"min":0,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"3657757d-b048-4916-99ba-8b7419977a65","name":"Out of Scope","targets":[{"id":"c856ece2-d10b-480d-8310-fb82e8ce490d","uri":"https://apuat-aaa.fisglobal.com","name":"Reference above out of scope targets","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e77bb669-652b-4f59-be4e-b05f8c7cf4f6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eUnless a return to scope date is explicitly specified, the following assets are considered indefinitely out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ecreditportal.arvest.com\u003c/li\u003e\n\u003cli\u003eapplicant.bankofeastman.com\u003c/li\u003e\n\u003cli\u003eapplynowportal.bankIowa.com\u003c/li\u003e\n\u003cli\u003eMyLoanPortal.commercebank.com\u003c/li\u003e\n\u003cli\u003eportaldev.fisglobal.com\u003c/li\u003e\n\u003cli\u003eloanapps.fcbca.com\u003c/li\u003e\n\u003cli\u003eoaportal.fnbgranbury.com\u003c/li\u003e\n\u003cli\u003eapplicationportal.icbc-uscards.com\u003c/li\u003e\n\u003cli\u003eportal.orientalbank.com\u003c/li\u003e\n\u003cli\u003emyloanportal.plainscapital.com\u003c/li\u003e\n\u003cli\u003eportaltest.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapplicantportal.primesouth.com\u003c/li\u003e\n\u003cli\u003eapply.riverwindbank.com\u003c/li\u003e\n\u003cli\u003eloanportal.troybankandtrust.com\u003c/li\u003e\n\u003cli\u003eloanportal.bankwithunited.com\u003c/li\u003e\n\u003cli\u003elendinghfs.hatborofed.com\u003c/li\u003e\n\u003cli\u003eloans.collinsstatebank.com\u003c/li\u003e\n\u003cli\u003eloans.fmberlin.com\u003c/li\u003e\n\u003cli\u003eloans.hickorypointbank.com\u003c/li\u003e\n\u003cli\u003eloans.pattersonstatebank.com\u003c/li\u003e\n\u003cli\u003elending.tristar.bank\u003c/li\u003e\n\u003cli\u003eidmt2.fisglobal.com\u003c/li\u003e\n\u003cli\u003eidmt3.fisglobal.com\u003c/li\u003e\n\u003cli\u003eloans.bankoffrankewing.com\u003c/li\u003e\n\u003cli\u003eCredit.arvest.com\u003c/li\u003e\n\u003cli\u003eapply.mysunwest.com\u003c/li\u003e\n\u003cli\u003eapplynow.bankiowa.com\u003c/li\u003e\n\u003cli\u003eoaloans.fnbgranbury.com\u003c/li\u003e\n\u003cli\u003eapply.bankwithunited.com\u003c/li\u003e\n\u003cli\u003eapplyonline.fcbca.com\u003c/li\u003e\n\u003cli\u003eoa-prod-orig.fisglobal.com\u003c/li\u003e\n\u003cli\u003eoa-prod-cde.fisglobal.com\u003c/li\u003e\n\u003cli\u003eoa-prod-flo.fisglobal.com\u003c/li\u003e\n\u003cli\u003eoa-prod-flo-noap.fisglobal.com\u003c/li\u003e\n\u003cli\u003ecreditcards.icbc-uscards.com\u003c/li\u003e\n\u003cli\u003eapply.Orientalbank.com\u003c/li\u003e\n\u003cli\u003eapplynow.primesouth.com\u003c/li\u003e\n\u003cli\u003eloanapp.riverwindbank.com\u003c/li\u003e\n\u003cli\u003emyloan.plainscapital.com\u003c/li\u003e\n\u003cli\u003emyloan.commercebank.com\u003c/li\u003e\n\u003cli\u003eaplica.orientalbank.com\u003c/li\u003e\n\u003cli\u003eloanapp.troybankandtrust.com\u003c/li\u003e\n\u003cli\u003eoa.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-arvest.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-bankiowa.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-commerce.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-fcbca.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-fnbgranbury.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-icbc.fisglobal.com\u003c/li\u003e\n\u003cli\u003eID-UAT2.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-plainscapitol.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-primesouth.fisglobal.com\u003c/li\u003e\n\u003cli\u003eap-uat3.fisglobal.com \u003c/li\u003e\n\u003cli\u003eID-UAT1.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-riverwindbank.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-troybankandtrust.fisglobal.com\u003c/li\u003e\n\u003cli\u003eapuat-unitedbankshares.fisglobal.com\u003c/li\u003e\n\u003cli\u003eid-uat.fisglobal.com\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e(Testing for the out-of-scope instances above can be done on these sites only!--\u0026gt; oa-beta.fisglobal.com/oa/fi/10177, oa-qa.fisglobal.com/oa/fi/10349, qat3-InternetDirect.fisglobal.com, qat5-internetdirect.fisglobal.com, qat12-internetdirect.fisglobal.com, qat7-internetdirect.fisglobal.com, qat8-internetdirect.fisglobal.com, qat9-internetdirect.fisglobal.com, qat11-internetdirect.fisglobal.com)\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe assets below are also out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003epayrix assets (effective 3/7/2023)\u003c/li\u003e\n\u003cli\u003esedgwick assets\u003c/li\u003e\n\u003cli\u003esungard availability services assets\u003c/li\u003e\n\u003cli\u003eAll Github/Postman Repos\u003c/li\u003e\n\u003cli\u003e*.automatedfinancial.com\u003c/li\u003e\n\u003cli\u003eapp.fisglobal.teamsupport.com (any and all apps/FIS instances relating to 3rd party owned and hosted TeamSupport application)\u003c/li\u003e\n\u003cli\u003e*.internet-estatements.com \u003c/li\u003e\n\u003cli\u003ebrandzone.fisglobal.com - this asset is owned/hosted and managed by a 3rd party. \u003c/li\u003e\n\u003cli\u003eWorldpay assets are OOS as Worldpay is not an FIS owned entity.\u003c/li\u003e\n\u003cli\u003efisprotects*.fisglobal.com \u0026amp;  protect*.fidelityifs.com (Issueless Positive Pay) \u003c/li\u003e\n\u003cli\u003eWSO2-based applications and services\u003c/li\u003e\n\u003cli\u003ena-adeptiaportal.fisglobal.com (any and ALL FIS instances/environments that are adeptia)\u003c/li\u003e\n\u003cli\u003erdocs.fisglobal.com, relius.net, yourbenefitaccount.com, accountplanaccess.com (Relius is OOS, all instances and environments.) \u003c/li\u003e\n\u003cli\u003e*.avantgardportal.com, *.ebam.myfis.cloud, *ebam.fiscloudservices.com (AvantGard is OOS, all instances and environments) \u003c/li\u003e\n\u003cli\u003e*woseforms.fisglobal.com (effective 3/16/2026 any and all instances of woseforms.fisglobal.com is OOS. This will be OOS indefinitely as this application is owned, hosted, and managed by a 3rd party)\u003c/li\u003e\n\u003cli\u003eFIS IdP Codebase/Assets\u003c/li\u003e\n\u003cli\u003eRegulatory University assets (e.g., *.regulatoryu.com)\u003c/li\u003e\n\u003cli\u003efranklintempleton*.canadaaccounts.ca, and franklintempleton*.ca-onlineaccounts.ca (all instances and environments) (OOS until 12/01/2026)\u003c/li\u003e\n\u003cli\u003e*-scm.fisglobal.com and *-ecm.fisglobal.com assets (All instances and environments of SCM and ECM assets are OOS effective 9/3/2026 - 11/15/2026)\u003c/li\u003e\n\u003cli\u003e*.fiswebdev.net (All instances and environments of DNN assets are OOS effective 8/19/2026 - 11/1/2026)\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"3af2dbba-aefb-4935-958b-527a41aaa9b6","name":"Additional in scope","targets":[{"id":"3eddde01-261c-4f7b-88bb-705b89eef49c","uri":null,"name":"https://www.tdfitloan.com/#!/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"98a20179-46b2-4325-8b65-59e12c92421c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"da306d71-3cd3-485d-a199-1f9412939e89","p1MaxCents":2000000,"p1MinCents":1000000,"p2MaxCents":1000000,"p2MinCents":250000,"p3MaxCents":250000,"p3MinCents":20000,"p4MaxCents":20000,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":10000,"max":20000},"2":{"min":2500,"max":10000},"3":{"min":200,"max":2500},"4":{"min":0,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"54eaced8-20d0-4724-8fe4-eb3873414eb5","code":"fis","state":"in_progress","endsAt":null,"bountyId":"af974039-db2f-406a-9623-21ad0a14d428","startsAt":"2021-08-10T05:30:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2617/46f9/8dbd1e55/62621542a061dcc0af8fe3e00062015a_x0QJftTr_400x400.jpeg","logoBackgroundColor":"#4BCD3E","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-08-10T05:30:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fis","changelogs":"/engagements/fis/changelog","submissions":null,"announcements":"/engagements/fis/announcements","hallOfFame":"/engagements/fis/hall_of_fames","crowdstream":null},"announcementsCount":108,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/fis/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fis\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fis/engagement_subscribers","engagementChangelogsUrl":"/engagements/fis/changelog","publishedAt":"2026-09-15T16:18:17.080Z","engagementChangelogUrl":"/engagements/fis/changelog/94ae44bf-701a-47f9-b1cc-052c0b8db3d5","createUserFeedbacksUrl":"/engagements/fis/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}