{"id":"e39ebfc2-5ea6-4be5-95db-b0087697d611","engagementId":"32183b8a-4bf1-483f-beb6-e051ea9d0dce","data":{"brief":{"id":"e44eecf3-d328-4925-9c0b-713ba0488aeb","name":"Progress Software – Progress Data Cloud","tagline":"Dedicated to propelling business forward in a technology-driven world, Progress (Nasdaq: PRGS) helps businesses drive faster cycles of innovation, fuel momentum and accelerate their path to success","description":"\u003cp\u003eProgress believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our application. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Progress Software not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Progress Software, you can report it via our \u003ca href=\"https://www.progress.com/security/vulnerability-reporting-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVulnerability Disclosure Program\u003c/a\u003e. The following guidelines are to be adhered to at all times:\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThe use of Automated scanners against public websites is strictly prohibited\u003c/strong\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or bruteforce issues on non-authentication endpoints\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003ePhishing customers or employees of Progress Software. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eDisclosure Policy\u003c/h2\u003e\n\n\u003cp\u003ePlease do not discuss any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003cli\u003eProgress employees, Progress contractors, or Progress suppliers may not submit to this program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[],"resources":[],"engagement":{"id":"32183b8a-4bf1-483f-beb6-e051ea9d0dce","code":"progressdatacloud-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"40278f9d-31ab-4d74-8f2a-65b2a88e3a9f","startsAt":"2024-12-12T20:36:40Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/21d2/8f11/18ad1666/99ab949dee8590e9d4d29a2a54b6bc49_e2784eee6f66c08da36d7641bfaf1537_progress.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-12-12T20:36:40.756Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/progressdatacloud-vdp-pro","changelogs":"/engagements/progressdatacloud-vdp-pro/changelog","submissions":null,"announcements":"/engagements/progressdatacloud-vdp-pro/announcements","hallOfFame":"/engagements/progressdatacloud-vdp-pro/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/progressdatacloud-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=progressdatacloud-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/progressdatacloud-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/progressdatacloud-vdp-pro/changelog","publishedAt":"2026-05-13T22:09:19.572Z","engagementChangelogUrl":"/engagements/progressdatacloud-vdp-pro/changelog/e39ebfc2-5ea6-4be5-95db-b0087697d611","createUserFeedbacksUrl":"/engagements/progressdatacloud-vdp-pro/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}