generated: '2026-07-28' method: searched probe: true source: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html scope: >- Oracle Hospitality has no product-specific disclosure programme; it inherits Oracle Corporation's company-wide vulnerability handling policy, which is also the policy declared on the public oracle/hospitality-api-docs specification repository. policy: - https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html - https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ - https://github.com/oracle/hospitality-api-docs/blob/main/SECURITY.md contact: - secalert_us@oracle.com encryption_key: https://www.oracle.com/security-alerts/encryptionkey.html security_txt: published: false probed: - url: https://www.oracle.com/.well-known/security.txt status: 403 - url: https://docs.oracle.com/.well-known/security.txt status: 404 bug_bounty: published: false note: >- Oracle does not operate a public bug bounty. Researchers are credited in the applicable Critical Patch Update, Critical Security Patch Update or Security Alert advisory when a fix ships. reporting_channels: - audience: Oracle customers and partners channel: Designated support mechanism (My Oracle Support or SuiteSupport) service request - audience: Everyone else channel: Email secalert_us@oracle.com, PGP encryption encouraged coordinated_disclosure_terms: - Do not publish the vulnerability before Oracle releases a fix. - Do not disclose exact details of the issue, such as exploits or proof-of-concept code. - Coordinate disclosure with Oracle to allow sufficient time for remediation. - Oracle does not credit employees or contractors of Oracle and its subsidiaries. patch_cadence: programme: Oracle Critical Patch Update advisories: https://www.oracle.com/security-alerts/ evidence: - source: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html kind: disclosure-policy-page status: 200 quote: >- If you are not an Oracle customer or partner, please email secalert_us@oracle.com with your discovery. - source: https://github.com/oracle/hospitality-api-docs/blob/main/SECURITY.md kind: repository-security-policy status: 200 quote: >- Please do NOT raise a GitHub Issue to report a security vulnerability. If you believe you have found a security vulnerability, please submit a report to secalert_us@oracle.com preferably with a proof of concept.