generated: '2026-08-13' method: searched source: >- https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html (HTTP 200), https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure.html (HTTP 200), https://www.oracle.com/security-alerts/ (HTTP 200) provider: Oracle Siebel providerId: oracle-siebel published: true program_type: coordinated-disclosure bug_bounty: false summary: >- Oracle operates a corporate coordinated-disclosure programme that covers every Oracle product, Siebel CRM included. There is no Siebel-specific policy and no paid bug bounty: Oracle explicitly states it does not distribute exploit or proof-of-concept code and does not give advance notification to individual customers. Fixes ship on the quarterly Critical Patch Update cycle, with out-of-band Security Alerts for severe issues. policy_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/disclosure.html reporting_url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html advisories_url: https://www.oracle.com/security-alerts/ security_txt: false security_txt_note: >- Oracle serves no /.well-known/security.txt. www.oracle.com returns HTTP 403 to an unauthenticated request for that path (edge challenge) and docs.oracle.com returns 404 — see well-known/oracle-siebel-well-known.yml. contacts: - channel: email value: secalert_us@oracle.com audience: >- Researchers who are not Oracle customers or partners. Oracle asks that sensitive material be encrypted with its published public PGP key. - channel: my-oracle-support value: https://support.oracle.com/ audience: >- Oracle customers and partners, who are asked to raise a service request rather than email. disclosure_terms: - >- Researchers must follow responsible disclosure to be eligible for credit: do not publish before Oracle releases a fix, and do not disclose exact details such as exploits. - >- Oracle provides no information about vulnerability specifics beyond the Critical Patch Update or Security Alert advisory, prerelease note, preinstallation notes, readme files and FAQs. - Oracle does not provide advance notification to individual customers. - Oracle does not distribute exploit code or proof-of-concept code. remediation_cadence: program: Critical Patch Update frequency: quarterly out_of_band: Security Alerts url: https://www.oracle.com/security-alerts/ third_party_listings: - platform: HackerOne url: https://hackerone.com/oracle http_status: 200 type: response-policy-directory-entry bounty: false note: >- A HackerOne directory entry exists for Oracle. It is a response-policy listing, not a paid bounty programme; Oracle's own policy pages remain the authoritative route and direct reporters to secalert_us@oracle.com or My Oracle Support. scope_note: >- This is a parent-brand programme. Siebel CRM is an Oracle product and is covered by Oracle's corporate vulnerability handling; Oracle publishes no Siebel-specific disclosure policy. maintainers: - FN: Kin Lane email: kin@apievangelist.com