Dow | Synack
Synack Vulnerability Disclosure
Protect Dow by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.
Overview
This Responsible Disclosure Program (the “Program”) page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.
Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.
Guidelines
In submitting a request, you agree to:
- Accept and adhere to the Terms of Use.
- Work directly with Synack on vulnerability submissions.
- Provide detailed description of a proof of concept to detail reproduction of vulnerabilities.
- Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems.
- Do not engage in social engineering or phishing of customers or employees.
- Do not request compensation for time and materials or vulnerabilities discovered.
The following web applications are in scope:
- *.dow.com
- *.midlandresolution.com
- *.rohmandhaas.com.tr
- *.rohmhaaskimyasanayi.com.tr
- *.triverconservation.com
- *.univation.com
- *.dorinco.com
All other Dow systems and services are out of scope for the purpose of the Program.
If you aren’t sure whether a particular Dow system or service is a Target, contact us at vulnerabilitydisclosure@dow.com before starting your research and testing. If there is an out-of-scope Dow system or service that you think merits research and testing, contact us before starting your research and testing.
Rules of Engagement
- No Denial of Service testing
- No Physical or Social Engineering
- No testing of Third-party Services
- No uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)
- All attack payload data must use professional language
- If able to gain access to a system, accounts, users, or user data, stop at point of recognition and report. Do not dive deeper to determine how much more is accessible.
Out of Scope – Low Impact Vulnerabilities
The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:
- Google Maps API Keys
- Account/e-mail enumeration using brute-force attacks
- Any low impact issues related to session management
- Bypassing content restrictions in uploading a file without proving the file was received
- Clickjacking/UI redressing
- Client-side application/browser autocomplete or saved password/credentials
- Descriptive or verbose error pages without proof of exploitability or obtaining sensitive information
- Directory structure enumeration
- Incomplete or missing SPF/DMARC/DKIM records
- Issues related to password/credential strength, length, lockouts, or lack of brute-force/rate-limiting protections
- Lack of SSL or Mixed content
- Login/Logout/Unauthenticated/Low-impact CSRF
- Low impact Information disclosures
- Missing Cookie flags
- Missing/Enabled HTTP Headers/Methods which do not lead directly to a security vulnerability
- Reflected file download attacks (RFD)
- Self-exploitation (i.e. password reset links or cookie reuse)
- URL/Open Redirection
- Valid bugs or best practice issues that are not directly related to the security posture of the client
- Vulnerabilities affecting users of outdated browsers, plugins or platforms
- Vulnerabilities that allow for the injection of arbitrary text without allowing for hyperlinks, HTML, or JavaScript code to be injected
- Vulnerabilities that require the user/victim to perform extremely unlikely actions
Privacy Policy
We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy. When you access or use our Site, you signify your agreement to this Privacy Policy.
Information We Collect
When you access or use our Sites we collect certain categories of information about you from a variety of sources. Some features of our Sites may require you to directly enter certain information about yourself:
- When you contact us. You provide personal information when contacting us through our Sites. For example, we will collect your first and last name, user name, company name, job title, email address, postal address, and phone number when you ask to download content (such as white papers), register for a webcast or other event, or subscribe to email lists.
- When you create a customer account on our platform. When you create a customer account on our platform you will be required to provide us with your first and last name and email address.
How We Use Information We Collect
In order to fulfill our contract with you, we process your personal information to administer your account and provide the services described in our Terms of Use.
Additionally, in order to be responsive to you, to provide effective services to you, and to maintain our business relationship, we will use the information we collect from you to:
- Personalize our Sites
- Monitor and analyze trends, usage and activity
- Measure and understand the effectiveness of the content
- Communicate with you
- Keep our Sites safe and secure
Contacting Synack
For questions about accessing, changing, or deleting your personal information, please visit http://www.synack.com/ or contact us at +1 (855) 796-2251 or via email at privacy@synack.com.
Company Name
Dow
Website
https://www.dow.com
About
Dow Inc. is a global materials science company providing science-based products and solutions across packaging, infrastructure, and consumer care markets.
By submitting a vulnerability to our responsible disclosure program, you agree to the Terms of Use.