{"id":"593f03de-8458-4647-901f-1a8f2e755028","engagementId":"a55dc712-8a30-4d82-a305-09e4fe8fbc33","data":{"brief":{"id":"44d01ba0-2dc6-4f81-8940-b8e9687b1227","name":"Stryker","tagline":"Stryker Vulnerability Disclosure Program","description":"\u003cp\u003eNo technology is perfect and Stryker believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our products. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eImportant information:\u003c/h2\u003e\n\n\u003cp\u003eWe will not engage in legal action against individuals who submit reports through our Vulnerability Reporting process and enter into a legal agreement with us. We agree to work with individuals who:    \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eEngage in testing of systems/research without harming Stryker or its customers.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003ePerform tests on products without affecting customers, or receive permission/consent from customers before engaging in vulnerability testing against their devices/software, etc.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eEngage in vulnerability testing within the scope of our vulnerability disclosure program in accordance with the terms and conditions of any agreements entered into between Stryker and individuals.\u003c/li\u003e\n\u003cli\u003eAdhere to the laws of their location and the location of Stryker. For example, violating laws that would only result in a claim by Stryker (and not a criminal claim) may be acceptable as Stryker is authorizing the activity (reverse engineering or circumventing protective measures) to improve its system.\u003c/li\u003e\n\u003cli\u003eRefrain from disclosing vulnerability details before any mutually agreed-upon timeframe expires.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePreference, prioritization, and acceptance criteria\u003c/h3\u003e\n\n\u003cp\u003eWe will use the following criteria to prioritize and triage submissions.\u003cbr\u003e\u003cbr\u003e\nWhat we would like to see from you:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports written in English.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eReports that include proof‐of‐concept code, which will better equip us to triage.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eHow you found the vulnerability, the impact, and any potential remediation.\u003cbr\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote: Reports that include only crash dumps or other automated tool output may receive lower priority.\u003c/p\u003e\n\n\u003ch3\u003eWhat you can expect from us:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eA timely response to your email (within 5 business days).\u003c/li\u003e\n\u003cli\u003eWe will direct the potential findings to the appropriate product teams for verification and reproduction. You may be contacted to provide additional information at this stage.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eWe will, following investigation of a report, confirm the existence of the vulnerability and the potential impact.  - If the identified vulnerability is determined to impact patient safety, we will work expeditiously to develop a resolution and take appropriate action. All other vulnerabilities will be evaluated and addressed based upon the associated risk.\u003c/li\u003e\n\u003cli\u003eAn open dialog to discuss issues.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eNotification when the vulnerability analysis has completed each stage of our review.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eCredit after the vulnerability has been validated and resolved, if desired.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eWe are committed to being as transparent as possible about the remediation timeline and issues or challenges that may be involved.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eIf we are unable to resolve communication issues or other problems, we may bring in a neutral third party (such as CERT/CC, ICS-CERT, or the relevant regulator) to assist in determining how best to handle the vulnerability.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eAll aspects of this process are subject to change without notice, as well as for case-by-case exceptions. No particular level of response is guaranteed.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNotice:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eIn the event, you decide to share any information with Stryker, you agree that the information you submit will be considered as non-proprietary and non-confidential and that Stryker is allowed to use such information in any manner, in whole or in part, without any restriction. Furthermore, you agree that submitting information does not create any rights for you or any obligation for Stryker.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"50214b57-2dde-40fd-ae5a-6680372523d4","targetsOverview":"\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eNo credentials are provided for this program. \u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked, such as dark web forums or leaked credential sites, you can report it to this engagement. However, be aware that it is only eligible for P5 designation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance. Unless significant demonstrable impact is indicated in a clear and reproducible manner.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"777683da-24bb-41ad-87cd-8b40065d681a","name":"In Scope Targets","targets":[{"id":"f18cbce1-287a-4a8c-aa6c-eabd3028beea","uri":"","name":"All public facing Stryker assets ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a388d45d-d9a1-48e1-a469-ccc3aadd50f6","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"f18cbce1-287a-4a8c-aa6c-eabd3028beea"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f18cbce1-287a-4a8c-aa6c-eabd3028beea"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"120edaae-0e04-4137-827d-76a73195a90e","name":"Out of Scope","targets":[{"id":"caabac2a-e9d8-4da5-9ef4-e91d8a8c6aff","uri":"","name":"Any asset or technology not explicitly owned by Stryker.","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"56763e3d-8f9c-479f-897c-4d59e9d6dfcf","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"a55dc712-8a30-4d82-a305-09e4fe8fbc33","code":"stryker-vdp","state":"in_progress","endsAt":null,"bountyId":"aee3c0be-568d-4d5f-913e-9e4215d41fdc","startsAt":"2022-04-14T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Healthcare","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/97c5/6b29/fb24bd6a/6d3b3d6a5d141cb51df33b1df03fb3e4_stryker.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-04-14T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/stryker-vdp","changelogs":"/engagements/stryker-vdp/changelog","submissions":null,"announcements":"/engagements/stryker-vdp/announcements","hallOfFame":"/engagements/stryker-vdp/hall_of_fames","crowdstream":"/engagements/stryker-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/stryker-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=stryker-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/stryker-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/stryker-vdp/changelog","publishedAt":"2026-02-25T23:54:19.124Z","engagementChangelogUrl":"/engagements/stryker-vdp/changelog/593f03de-8458-4647-901f-1a8f2e755028","createUserFeedbacksUrl":"/engagements/stryker-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/stryker-vdp/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}