{"id":"a633b6d5-78fd-4c45-bd45-7f2466803723","engagementId":"fbd6c324-4a53-41d8-991b-21bdd395b8f2","data":{"brief":{"id":"4f287685-86ec-41ee-94dd-902bd25a2829","name":"Unisys Managed Bug Bounty Engagement","tagline":"Unisys is a global technology solutions company that empowers organizations worldwide with digital workplace, cloud, applications, infrastructure, enterprise computing, and business process solutions.","description":"\u003cp\u003eWe are a global technology solutions company that powers breakthroughs for the world’s leading organizations. These solutions — digital workplace, cloud, applications \u0026amp; infrastructure, enterprise computing and business process solutions — help people overcome obstacles and not only reach their greatest potential but go beyond it.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Unisys believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Unisys not listed in the targets section is out of scope for this program. This includes any/all subdomains not listed above. While we have identified these assets as the primary targets, we understand that our digital footprint may extend beyond this list. Therefore, we welcome researchers to identify and report vulnerabilities in other Unisys-owned assets in our \u003ca href=\"https://bugcrowd.com/engagements/unisys-vdp-pro\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVDP\u003c/a\u003e, as long as they fall under our ownership and are not explicitly excluded from the program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eAccess\u003c/h3\u003e\n\n\u003cp\u003eAll of the targets are accessible via the public internet and available \u003c/p\u003e\n\n\u003ch3\u003eTraffic Identification\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior:\u003cbr\u003e\n\u003ccode\u003eX-Bugcrowd:\u0026lt;bugcrowdusername\u0026gt;\u003c/code\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEligibility\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll vulnerabilities must be reported exclusively through the Bugcrowd platform.\u003c/li\u003e\n\u003cli\u003eParticipants must not be residents of countries under any trade restrictions or sanctions.\u003c/li\u003e\n\u003cli\u003eEmployees of Unisys and their immediate family members are not eligible for rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cp\u003eThe following submissions are excluded from this program, but can be considered for our \u003ca href=\"https://bugcrowd.com/engagements/unisys-vdp-pro\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVDP\u003c/a\u003e.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eIssues with corresponding patches that are younger than 60 days\u003c/li\u003e\n\u003cli\u003eUser Enumeration\u003c/li\u003e\n\u003cli\u003eConcurrent login caching API calls\u003c/li\u003e\n\u003cli\u003eSession validation after password reset or change\u003c/li\u003e\n\u003cli\u003eSubdomain Takeover\u003c/li\u003e\n\u003cli\u003eStealer Logs\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 31/01/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003eAny subdomain that redirects to non-unisys domain will be considered out of scope.\u003c/li\u003e\n\u003cli\u003eWe will consider the cross-site scripting issue in gls*.*.unisys as low severity.\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny submissions pertaining to WSO2 products will be considered out of scope and will not be eligible for bounty.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003ePotential post-exploitation scenarios\u003c/strong\u003e: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"8196f6f9-e1da-43a3-b21b-bfe9979ac0bc","name":"In Scope","targets":[{"id":"a626068f-9c9b-40b2-8e5c-d706e62e9b07","uri":"http://unisys.com/","name":"*.unisys.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5e9d1220-171a-45e1-83b3-6f740a8eeb85","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"}],"recentChangeFlags":null},{"id":"fb14b844-3818-4913-afbb-b00c95d9443a","uri":"http://unifysquare.com/","name":"*.unifysquare.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7333de81-7980-4a44-9d20-57b252e551b2","sortOrder":1},"sortOrder":1,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c8372db1-2645-498d-b3d8-5d278f3c1880","p1MaxCents":450000,"p1MinCents":300000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":50000,"p3MinCents":25000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":3000,"max":4500},"2":{"min":1000,"max":2000},"3":{"min":250,"max":500},"4":{"min":50,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"fbd6c324-4a53-41d8-991b-21bdd395b8f2","code":"unisys-mbb-og","state":"in_progress","endsAt":null,"bountyId":"95b04c98-73f1-49fc-8682-a51b3881e533","startsAt":"2025-01-28T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/b15b/56ea/0b98ebaf/aed3327da7fd379db77be478c195233b_unisys_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-01-28T19:00:02.823Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/unisys-mbb-og","changelogs":"/engagements/unisys-mbb-og/changelog","submissions":null,"announcements":"/engagements/unisys-mbb-og/announcements","hallOfFame":"/engagements/unisys-mbb-og/hall_of_fames","crowdstream":"/engagements/unisys-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/unisys-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=unisys-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/unisys-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/unisys-mbb-og/changelog","publishedAt":"2026-09-21T15:46:55.429Z","engagementChangelogUrl":"/engagements/unisys-mbb-og/changelog/a633b6d5-78fd-4c45-bd45-7f2466803723","createUserFeedbacksUrl":"/engagements/unisys-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/unisys-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}