Vulnerability Disclosure Program

Vulnerability Disclosure Program

Products & Services

Committed to Coordination
If you have information related to security vulnerabilities of EME Blue – Engines products or services, we want to hear from you. Please submit a report in accordance with the guidelines below. We value the positive impact of your work and thank you in advance for your contribution.

Guidelines

EME Blue – Engines agrees to not pursue civil claims against researchers related to the disclosures submitted through this website who:

– Do not cause harm to EME Blue – Engines, our customers, or others;

– Provide a detailed summary of the vulnerability, including the target, steps, tools, and artefacts used during discovery (the detailed summary will allow us to analyze and the vulnerability) and take precautious measure to prevent them as much as doable and possible;

– Do not compromise the privacy or safety of our customers and the operation of our services. Specifically;

– Contact us immediately if you inadvertently encounter user data;

– Do not view, alter, save, store, transfer, or otherwise access the data, and immediately purge any local information upon reporting the vulnerability to EME Blue – Engines;

– Act in good faith to avoid privacy violations, destruction of data, and interruption or degradation of our services (including denial of service).

Compliance

Comply with all applicable laws;
Do not violate any other law (other than those that would result only in claims by EME Blue – Engines), or disrupt or compromise any data or vehicle that is not their own;
Publicly disclose vulnerability details only after EME Blue – Engines confirm completed remediation of the vulnerability and not publicly disclose vulnerability details if there is no completion date or completion cannot be ascertained;

Out of Scope

Reports from automated tools or scans issues without clearly identified security impact (such as click jacking on a static website), missing security headers, or descriptive error messages;

Missing best practices, information disclosures, use of a known-vulnerable libraries or descriptive / verbose / unique error pages (without substantive information indicating exploitability);
Speculative reports about theoretical damage without concrete evidence or some substantive information indicating exploitability and/or forms missing CSRF tokens without evidence of the actual CSRF vulnerability;
Self-exploitation (e.g., cookie reuse);
Reports of insecure SSL/TLS ciphers (unless you have a working proof of concept, and not just a report from a scanner such as SSL Labs).

EME Blue - Engines Property

Any physical attempt against EME Blue – Engines property or data centre(s) Presence of autocomplete attribute on web forms;
Cookie flags on non-sensitive cookies;
Denial of Service Attacks;
Banner identification issues (e.g., identifying what web server version is used); Open ports, which do not lead directly to:
– Vulnerability
– Open redirect vulnerabilities Publicly accessible login panels – Click jacking
– Content spoofing / text injection
– Non EME Blue – Engines hosted dealership websites
– Safe Harbour

Vulnerability Program

EME Blue – Engines agrees not to pursue civil action against researchers who comply with EME Blue – Engines policies regarding this vulnerability disclosure program. We consider activities conducted consistent with the EME Blue – Engines -Policy Terms to constitute conduct under the applicable Computer Fraud and Abuse Act. Also, if you comply with the EME Blue – Engines Policy Terms, we will not bring a claim against you for circumventing the technological measures we have used to protect the applications in scope.

Transfer & Storage of Data

If a third-party initiates legal action against you, and you have complied with the EME Blue – Engines Policy Terms, we will, if asked, state that your actions were conducted in compliance with this policy. Herefore you prior consent that your Information may be transferred to and stored by EME Blue – Engines, and acknowledge that you have read and accepted the Terms, Privacy Policy and Disclosure Guidelines presented to you when you created your account at EME Blue – Engines.

You cannot copy content of this page