{"id":"e318f8af-0bc0-4f0a-89ec-066d6d19c4aa","engagementId":"4c211ee2-78d6-4233-bdef-6050ce9be810","data":{"brief":{"id":"04626d5d-6654-4854-8c29-5153df8d9857","name":"Unisys Vulnerability Disclosure Engagement","tagline":"Unisys is a global technology solutions company that empowers organizations worldwide with digital workplace, cloud, applications, infrastructure, enterprise computing, and business process solutions.","description":"\u003ch1\u003eIntroduction\u003c/h1\u003e\n\n\u003cp\u003eUnisys believes effective disclosure of security vulnerabilities requires mutual trust, respect, transparency and common good between Unisys and Security Researchers. Together, our vigilant expertise promotes the continued security and privacy of Unisys customers, products, and services.\u003c/p\u003e\n\n\u003ch1\u003eSecurity Researchers\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll vulnerabilities must be reported exclusively through the Bugcrowd platform.\u003c/li\u003e\n\u003cli\u003eParticipants must not be residents of countries under any trade restrictions or sanctions.\u003c/li\u003e\n\u003cli\u003eEmployees of \u003cstrong\u003eUnisys\u003c/strong\u003e and their immediate family members are not eligible for rewards.\u003c/li\u003e\n\u003cli\u003eUnisys defines a security vulnerability as an unintended weakness or exposure that could be used to compromise the integrity, availability or confidentiality of our products and services.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch1\u003eOut-of-Scope Vulnerabilities\u003c/h1\u003e\n\n\u003cp\u003eCertain areas are not covered under this vulnerability disclosure policy. These include, but are not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eThird-Party Services\u003c/strong\u003e: Issues related to services provided by external vendors, even if accessed through our platforms or subdomains.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePhysical Security\u003c/strong\u003e: Vulnerabilities related to physical access or security of Unisys facilities.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSocial Engineering\u003c/strong\u003e: Attempts to exploit or manipulate individuals to gain unauthorized access.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDenial of Service (DoS) Attacks\u003c/strong\u003e: Testing aimed at disrupting the availability of our services.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAlready Known Issues\u003c/strong\u003e: Vulnerabilities that are already documented or reported through other channels.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLow Vulnerabilities\u003c/strong\u003e: XFS, username enumeration, OPTIONS, Headers missing etc.\u003c/li\u003e\n\u003cli\u003e Any subdomain that redirects to non-unisys domain will be considered out of scope.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eData Handling and Impact\u003c/h1\u003e\n\n\u003cp\u003eResearchers are expected to avoid data exfiltration and should not cause any damage during their testing. If you discover a vulnerability such as SQL injection or remote code execution, please do not attempt to extract or manipulate data. Your focus should be on identifying and reporting the vulnerability without exploiting it further or causing any disruption to our services.\u003c/p\u003e\n\n\u003ch1\u003eOur Commitment to Researchers\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eTrust\u003c/strong\u003e: We maintain trust and confidentiality in our professional exchanges with security researchers.\u003cbr\u003e\n\u003cstrong\u003eRespect\u003c/strong\u003e: We treat all researchers with respect and recognize your contribution for keeping our customers safe and secure.\u003cbr\u003e\n\u003cstrong\u003eTransparency\u003c/strong\u003e: We will work with you to validate and remediate reported vulnerabilities in accordance with our commitment to security and privacy.\u003cbr\u003e\n\u003cstrong\u003eCommon Good\u003c/strong\u003e: We investigate and remediate issues in a manner consistent with protecting the safety and security of those potentially affected by a reported vulnerability.\u003c/p\u003e\n\n\u003ch1\u003eWhat We Ask of Researchers\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eTrust\u003c/strong\u003e: We request that you communicate about potential vulnerabilities in a responsible manner, providing sufficient time and information for our team to validate and address potential issues.\u003cbr\u003e\n\u003cstrong\u003eRespect\u003c/strong\u003e: We request that researchers make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing.\u003cbr\u003e\n\u003cstrong\u003eTransparency\u003c/strong\u003e: We request that researchers provide the technical details and background necessary for our team to identify and validate reported issues, using the form below.\u003cbr\u003e\n\u003cstrong\u003eCommon Good\u003c/strong\u003e: We request that researchers act for the common good, protecting user privacy and security by refraining from publicly disclosing unverified vulnerabilities until our team has had time to validate and address reported issues.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"53664be8-8d7d-4aab-b752-6b4ef531dde3","name":"In scope","targets":[{"id":"a626068f-9c9b-40b2-8e5c-d706e62e9b07","uri":"http://unisys.com/","name":"*.unisys.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"560c31fa-1662-4824-94c6-68cc446eba82","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"a626068f-9c9b-40b2-8e5c-d706e62e9b07"}],"recentChangeFlags":null},{"id":"fb14b844-3818-4913-afbb-b00c95d9443a","uri":"http://unifysquare.com/","name":"*.unifysquare.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ad5117a1-7dc9-4c14-b7c3-525acd4d13f4","sortOrder":1},"sortOrder":1,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"fb14b844-3818-4913-afbb-b00c95d9443a"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eWhile we have identified these assets as the primary targets, we understand that our digital footprint may extend beyond this list. Therefore, we welcome researchers to identify and report vulnerabilities in other Unisys-owned assets, as long as they fall under our ownership and are not explicitly excluded from the program.\u003c/p\u003e\n\n\u003chr\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"4c211ee2-78d6-4233-bdef-6050ce9be810","code":"unisys-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"95b04c98-73f1-49fc-8682-a51b3881e533","startsAt":"2024-11-26T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/b15b/56ea/0b98ebaf/aed3327da7fd379db77be478c195233b_unisys_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-11-26T19:00:00.035Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/unisys-vdp-pro","changelogs":"/engagements/unisys-vdp-pro/changelog","submissions":null,"announcements":"/engagements/unisys-vdp-pro/announcements","hallOfFame":"/engagements/unisys-vdp-pro/hall_of_fames","crowdstream":"/engagements/unisys-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/unisys-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=unisys-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/unisys-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/unisys-vdp-pro/changelog","publishedAt":"2025-09-11T08:05:09.018Z","engagementChangelogUrl":"/engagements/unisys-vdp-pro/changelog/e318f8af-0bc0-4f0a-89ec-066d6d19c4aa","createUserFeedbacksUrl":"/engagements/unisys-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/unisys-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}