{"id":"82c0b7ed-46ed-4de8-8b89-98c6db7d6fce","engagementId":"df26f2e9-c7d1-46cc-b4ce-dd9cf3286938","data":{"brief":{"id":"2c83c0e1-1fb5-4159-aa19-67f3c4118543","name":"Imperva - Thales Bug Bounty","tagline":"Imperva, a Thales company, is the cybersecurity leader that helps organizations protect critical applications, APIs, and data, anywhere, at scale, and with the highest ROI. With an integrated approach combining edge, application security, and data security, Imperva protects companies through all stages of their digital journey. Imperva Threat Research and our global intelligence community enable Imperva to stay ahead of the threat landscape and seamlessly integrate the latest security, privacy, and compliance expertise into our solutions.","description":"\u003cp\u003eNo technology is perfect and Imperva believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Imperva or Thales not listed in the targets section is out of scope. This includes any/all subdomains not listed above. . If you happen to identify a security vulnerability on a target that is a \u003cstrong\u003ethird party supply chain provider\u003c/strong\u003e that is not in scope, but it demonstrably belongs to Imperva or Thales, you can report it in this program. However, be aware that it is ineligible for rewards or points-based compensation. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003e.imperva.com (protected by Imperva Web Application Firewall)\n     - With the exception of jamf.imperva.com and [*sso\u003c/em\u003e].imperva.com\u003c/li\u003e\n\u003cli\u003e*.incapsula.com (protected by Imperva Web Application Firewall)\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003e.cloudvector.com (protected by Imperva Web Application Firewall)\n-\u003c/em\u003e.supportportal.thalesgroup.com (protected by Imperva Web Application Firewall)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eNote about exposed secrets and credentials:\u003c/h2\u003e\n\n\u003cp\u003eReports of exposed secrets and credentials found on Github and similar code sharing sites will be evaluated accordingly:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIs the code a part of Imperva - Thales production environment and NOT a demo, proof of concept or ‘other’?\n\n\u003cul\u003e\n\u003cli\u003eIf they are not a part of critical infrastructure the submission may be determined to be ‘informational’ only.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThe secrets shared in the code were included on purpose or for convenience.\n\n\u003cul\u003e\n\u003cli\u003eIn some cases, the secrets may have been shared on purpose. In this case, it will be marked as ‘informational’.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eDetermination of the finding will be decided by Thales after review and any required investigations.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of scope:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eOpen redirects\u003c/li\u003e\n\u003cli\u003eCustomer consoles and management interfaces. Those areas where valid customer login and password are required to access.\u003c/li\u003e\n\u003cli\u003eAccessing, downloading, modifying, or disclosing any data other than your own data, including, without limitation, any Imperva customer information;\u003c/li\u003e\n\u003cli\u003eExecuting or attempting to execute any “Denial of Service” attack;\u003c/li\u003e\n\u003cli\u003ePosting, transmitting, uploading, linking to, sending, or storing any malicious software;\u003c/li\u003e\n\u003cli\u003eTesting in a manner that would result in the sending of unsolicited or unauthorized junk mail, spam, pyramid schemes, or other forms of unsolicited messages;\u003c/li\u003e\n\u003cli\u003eTesting in a manner that would degrade the operation of any Imperva products, services, systems, or networks;\u003c/li\u003e\n\u003cli\u003eTesting third-party applications, websites, or services that integrate with or link to Imperva applications, systems, and/or networks; \u003c/li\u003e\n\u003cli\u003eEngaging in any illegal activity. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"cda7da97-7123-4cf3-b0b0-3d3860b3d687","name":"In Scope Targets","targets":[{"id":"f09fe1f5-b8b0-401e-b6db-afbbf9c3ffbe","uri":"https://*.imperva.com","name":"https://*.imperva.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"27a75ee0-9656-493b-a75a-cd0cff808cdd","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f09fe1f5-b8b0-401e-b6db-afbbf9c3ffbe"},{"id":"d866e8ba-8dcd-4711-a16d-abaccdd975ec","name":"WAF/RASP Bypass","targetId":"f09fe1f5-b8b0-401e-b6db-afbbf9c3ffbe"}],"recentChangeFlags":null},{"id":"85f531b1-0d47-417f-8333-f812e2bc92d0","uri":"https://www.cloudvector.com/","name":"https://*.cloudvector.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5457d278-776e-47b7-91db-f455b308bde0","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"85f531b1-0d47-417f-8333-f812e2bc92d0"},{"id":"d866e8ba-8dcd-4711-a16d-abaccdd975ec","name":"WAF/RASP Bypass","targetId":"85f531b1-0d47-417f-8333-f812e2bc92d0"}],"recentChangeFlags":null},{"id":"a05dd1de-d9b6-43b4-b718-75dda5eafd5d","uri":"https://*.incapsula.com","name":"https://*.incapsula.com","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"af9a0f97-96a8-4968-98db-cea6e0060880","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a05dd1de-d9b6-43b4-b718-75dda5eafd5d"},{"id":"d866e8ba-8dcd-4711-a16d-abaccdd975ec","name":"WAF/RASP Bypass","targetId":"a05dd1de-d9b6-43b4-b718-75dda5eafd5d"}],"recentChangeFlags":null},{"id":"0f6915e1-b225-4732-b17e-f0b81924d41d","uri":"https://supportportal.thalesgroup.com","name":"https://supportportal.thalesgroup.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9a12a84f-d8a0-4c97-a45e-4d467297afbb","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"a92b3457-d017-418f-ab8d-18a357095b27","uri":"","name":"PTaaS Reference","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6bc9e6a2-d66f-4ee5-84f5-2a7a2bcea366","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"b406db1d-2bcf-452b-aeab-51f79047bc0d","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":125000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":45000,"p4MaxCents":20000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eImperva websites are in scope, in addition to websites and APIs from our acquisitions. In addition, our cloud WAF solution protects *.imperva.com and *incapsula.com and can be used to test various components relating to WAF bypass, bot protection or other website configurations. DDOS is never in scope and prohibited within this program (we get tested enough on this).\u003c/p\u003e\n\n\u003cp\u003eUnderstand that WAF bypass vulnerabilities are not automatically accepted. Our WAF solution is configurable and provides for allowing traffic as needed and configured for functionality.\u003c/p\u003e\n\n\u003cp\u003eImperva does not authorize, nor do we give permission for any testing against websites (our customers) not explicitly in this scope (corporate owned by Imperva), regardless of whether it is protected with our products.\u003c/p\u003e","rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1000,"max":1250},"3":{"min":450,"max":600},"4":{"min":150,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"591513f0-2309-482d-b320-1bff2f8b36d5","name":"Out of Scope","targets":[{"id":"12ac2733-9e20-4121-984d-0bc01c83f983","uri":"","name":"http://docs.imperva.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a0bea7b2-4f90-4eae-9ac5-2bfe775c3b67","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"6a343f50-0f61-4beb-9bc3-02f8de65ca80","uri":"","name":"http://docs-be.imperva.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6a2584e9-9182-49fb-8f88-8072c01d7d0a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"df26f2e9-c7d1-46cc-b4ce-dd9cf3286938","code":"imperva-mbb","state":"in_progress","endsAt":null,"bountyId":"d524c360-2601-4cb1-a7ed-e7b376ec94ae","startsAt":"2021-10-07T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/f21d/b772/5588d088/880f18934f656358ec6e39cb6b9ba71a_thales_156_white.png","logoBackgroundColor":"#242B75","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-10-07T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/imperva-mbb","changelogs":"/engagements/imperva-mbb/changelog","submissions":null,"announcements":"/engagements/imperva-mbb/announcements","hallOfFame":"/engagements/imperva-mbb/hall_of_fames","crowdstream":"/engagements/imperva-mbb/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/imperva-mbb/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=imperva-mbb\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/imperva-mbb/engagement_subscribers","engagementChangelogsUrl":"/engagements/imperva-mbb/changelog","publishedAt":"2025-03-04T18:29:53.735Z","engagementChangelogUrl":"/engagements/imperva-mbb/changelog/82c0b7ed-46ed-4de8-8b89-98c6db7d6fce","createUserFeedbacksUrl":"/engagements/imperva-mbb/feedbacks","engagementCrowdstreamUrl":"/engagements/imperva-mbb/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}