generated: '2026-08-27' method: searched source: >- https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ (HTTP 200 after a 301 from .../reporting.html) and https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ (HTTP 200) provider: Oracle Platforms providerId: oracle-platforms program: published: true name: Reporting Security Vulnerabilities to Oracle url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting/ policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ contact: secalert_us@oracle.com encryption: supported: true method: PGP note: >- Oracle publishes a PGP key and asks reporters to encrypt reports, proof-of-concept details, logs and attachments before transmission. bug_bounty: false bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program was found. Oracle runs a coordinated disclosure program with researcher credit rather than a paid bounty. remediation_channel: name: Critical Patch Update / Security Alert description: >- Oracle's stated policy is to credit the reporting researcher in the applicable Critical Patch Update, Critical Security Patch Update, or Security Alert advisory once a fix ships. researcher_requirements: - Follow responsible disclosure practices - Do not publish the vulnerability before Oracle ships a fix security_txt: served: false note: >- Oracle serves NO RFC 9116 /.well-known/security.txt on any host probed (www.oracle.com 302s to root then 403s at the edge; docs.oracle.com and cloud.oracle.com return a genuine 404). The disclosure program is real and well-documented — it is simply not machine-discoverable at the standard path. See well-known/oracle-platforms-well-known.yml for the full probe record.