Snapshot 19126
Normalized text
Scripts and page chrome removed; this is what change detection compares.
IBS Vulnerability Disclosure Program (VDP) IBS is committed to protecting the security, integrity, and privacy of our products and customer data. Introduction We welcome responsible security research and appreciate disclosures that help strengthen our systems. All reports are handled with seriousness, transparency, and respect for researcher effort. Program Guidelines To ensure safe and responsible reporting: Disclose vulnerabilities only to IBS; do not share findings externally until remediation is complete and both parties agree on the timeline. Include clear steps, PoC, screenshots/videos, and an assessment of the security impact. Exploit only what is necessary to confirm the vulnerability. Do not access, delete, or modify data, disrupt systems, pivot internally, or attempt persistence. Stop immediately if sensitive data is found and notify us. Avoid privacy violations, performance impact, or system degradation. IBS reserves full discretion on eligibility, severity, acknowledgement, and program updates. In-Scope Assets IBS-owned external-facing applications, services, APIs, mobile apps, and SaaS platforms that are operated or controlled by IBS. Out-of-Scope & Prohibited Activities Prohibited: DoS/DDoS, brute force, or automated high-volume scans Social engineering or phishing Physical security testing Use of leaked credentials Internal pivoting or accessing non-public systems Out-of-Scope Issues: SPF/DMARC/email hygiene suggestions without exploitability Clickjacking on non-sensitive pages Missing headers without a demonstrated or real impact Self-XSS Rate limiting without business risk Vulnerabilities in third-party systems Automated scanner results without reproduction steps or evidence Non-sensitive descriptive error messages with no security impact Certificate/TLS configuration notes without demonstrable risk Findings related to customer environments or custom deployments Reports citing outdated software versions without an exploitable vulnerability How to Report Include: Issue description and summary of the impact Reproduction steps Affected URLs, endpoints, parameters, request/response samples Screenshots or PoC Contact details Submit via: security [at] ibsplc.com PGP Key: https://www.ibsplc.com/.well-known/pgp-key.asc Our Commitment Acknowledge within 3 business days Remediate validated issues based on severity Publicly acknowledge (with consent) after resolution Safe Harbor IBS considers good-faith research following this policy to be authorized. We will not pursue legal action against researchers for testing conducted within the defined scope, provided there are no privacy breaches, system disruptions, or data destruction. If legal action is initiated by a third party against a researcher for activities carried out in accordance with this policy, IBS will make it known that the researcher's actions were authorized. Recognition This is not a monetary bug bounty program. However, we value our contributors and offer recognition through our Security Hall of Fame. Hall of Fame Eligibility: First valid report Found within scope Significant security/privacy impact Impactful vulnerabilities only Conclusion We appreciate your contribution to keeping IBS systems secure and thank the security community for its responsible efforts. Solutions Airline Retailing Cargo & Logistics Air Cargo Ocean Cargo Energy & Resources Logistics Loyalty Management Airline Operations Airport Management Airline Passenger Services Reservation Loyalty Staff & Corporate Travel Hospitality Solutions Tour & Cruise Consulting & Digital Transformation About Overview Leadership Customers Associations News & Events Offices Contact Resources Case Studies White Papers eBooks Blog Product Sheets Webcasts Careers Life @IBS Current Openings LCA Follow Us On Solutions Airline Retailing Airline Operations Hospitality Solutions Cargo & Logistics Air Cargo Ocean Cargo Energy & Resources Logistics Airport Management Tour & Cruise Loyalty Management Airline Passenger Services Reservation Loyalty Staff & Corporate Travel Consulting & Digital Transformation About Corporate Overview Leadership Customers Associations News & Events Careers Resources Case Studies White Papers eBooks Blog Product Sheets Contact Business Enquiry Media Enquiry Offices Navigation