Vulnerability Disclosure

BMC Helix welcomes reports of potential security vulnerabilities from customers and security researchers

Our team follows a formal escalation process for vulnerability disclosure regardless of the source, whether it is customers, researchers, internal QA teams, or others.

Based on the severity, the vulnerability is routed through senior management, remediated by the relevant development team, and communicated to affected customers.

process-for-vulnerability-disclosure

Reporting guidance

Report suspected vulnerabilities through established BMC Helix Support or security contact channels, and include enough context to support investigation (affected product/service and a clear description).

How to report a vulnerability?



Vulnerability response process

Our incident management procedure enables swift response to any potential incident. This procedure covers emergency incidents, escalation, and public vulnerability disclosure. BMC Helix’s practices include procedures for documenting the incident in detail and producing a report for future reference or management attention.

Assess impact — The application security team reviews the submitted data with the appropriate development team to assess the vulnerability’s impact and produce an internal severity rating.

Determine what fix is required — The development team attempts to reproduce the issue submitted then assesses the effort and resources required to fix the vulnerability or provide a workaround. They determine when the fix will be released based on the severity rating, the resources required, and the release lifecycle of the product.

Maintain communication — The application security team maintains open communication with the submitter until a fix or workaround is available.

Document and communicate fix — The development team sends a technical bulletin to all customers of the affected product, notifying them of the vulnerability and the availability of a fix or workaround.

Give credit where credit is due — Credit will be given to the submitter upon request.

bmc_helix_trust_center