If you have found one or more vulnerabilities in IT products, IT systems or IT services at Bremen University of Applied Sciences, you can contact us in confidence. We take every reported vulnerability seriously. We expect the points mentioned here to be adhered to.
We promise
- to treat every vulnerability report confidentially within the legal framework.
- not to pass on personal data to third parties without your express consent.
- to provide feedback on every vulnerability report made.
- not to initiate criminal proceedings against you as long as you have complied with the principles. This does not apply if recognisable criminal intentions have been or are being pursued.
- to publish your name/alias and, if applicable, a reference on the University of Bremen's acknowledgement website once the procedure has been completed. If you have provided personal data in the message or e-mail, please note the information on data protection.
We expect you to
- the vulnerability found has not been misused. This means that no damage has been caused beyond the reported vulnerability.
- no attacks (such as social engineering, spam, (distributed) DoS or "brute force" attacks, etc.) have been carried out against IT systems or infrastructures.
- no manipulation, compromising or modification of possible third-party systems or data has been carried out;
- no tools for exploiting vulnerabilities, e.g. on darknet markets, were offered for a fee or free of charge that could be used by third parties to commit criminal offences.
- the vulnerability report is not the result of automated tools or scans without explanatory documentation. These do not constitute valid vulnerability reports.
- the vulnerability report contains previously unknown information.
- valid contact details (e-mail address) are provided so that we can contact you in the event of queries. Particularly in the case of complex vulnerabilities, it cannot be ruled out that we will require further explanations and documentation. As we attach great importance to good communication, vulnerability reports without communication options can only be processed to a limited extent.