generated: '2026-09-13' method: searched source: https://support.novell.com/security-alerts/index.html name: Novell vulnerability disclosure description: >- Novell still serves a working vulnerability disclosure surface on support.novell.com, one of the few interactive (non-archival) pages left on the Novell brand domain. It publishes a reporting form, a named security contact, an encryption key, and an explicit taxonomy of what Novell considers a reportable vulnerability. Ownership has passed through Attachmate and Micro Focus to OpenText, which is visible in the contact address - it is security@microfocus.com, not a novell.com mailbox. program: type: disclosure-page bug_bounty: false url: https://support.novell.com/security-alerts/index.html http_status: 200 contact_email: security@microfocus.com encryption_key: https://support.novell.com/security-alerts/keypage.txt encryption_key_status: 200 encryption_key_format: PGP PUBLIC KEY BLOCK (GnuPG v2) submission: >- Web form on the disclosure page. Required fields are name, phone number, email address, affected Novell product and version, and a description of the issue. Reports may alternatively be emailed to the security contact, encrypted with the published PGP key. reportable_conditions: - An attacker is able to execute commands as another user - An attacker is able to access data contrary to the specified access restrictions for that data - An attacker is able to pose as another entity - An attacker is able to conduct a denial of service to legitimate users - An attacker is able to conduct information gathering activities - An attacker is able to hide attack-related activities - A capability behaves as expected but can be easily compromised - There is a primary point of entry vulnerable to attempts to gain inappropriate access scope_note: >- SUSE Linux vulnerabilities are routed away from this form to SUSE, which was separated from the Novell product line. General (non-security) defects go to support.novell.com/additional/bugreport.html, which now 302s into the OpenText SAML login at extlogin.opentext.com. security_txt: present: false note: >- No /.well-known/security.txt on www.novell.com (404) and the apex novell.com cannot be reached over TLS - see well-known/novell-well-known.yml. The disclosure program is published as an HTML page only. evidence: - url: https://support.novell.com/security-alerts/index.html status: 200 note: Live disclosure page with form, contact and taxonomy. - url: https://support.novell.com/security-alerts/keypage.txt status: 200 note: PGP public key block, 1762 bytes. - url: https://www.novell.com/.well-known/security.txt status: 404 - url: https://www.microfocus.com/en-us/support/security-vulnerability status: 302 note: Successor page redirects into the OpenText SAML login rather than serving public content.