Coordinated Vulnerability Disclosure (CVD) Policy

Version 1.0
Last Update: September 2026


Click here for English Version

Click here for German Version


English Version


The security of our systems and the protection of data are our top priorities. Despite careful security measures, security vulnerabilities may occasionally be overlooked. If you have discovered a vulnerability in our systems or services, we ask that you report it to us in a coordinated manner.


Scope

This Vulnerability Disclosure Policy defines the process through which security researchers and other parties can report potential vulnerabilities in Prologa products and services. The goal is to enable Prologa to investigate, assess, remediate, and communicate vulnerabilities in a coordinated manner before detailed information about these vulnerabilities becomes publicly known.

Excluded from scope: IT systems of third parties or partners associated with us.


Point of Contact

The Prologa Product Security Response Team is responsible for investigating all reported vulnerabilities, working closely with the reporters and Prologa’s product development team to address these vulnerabilities, and informing customers on how to implement the corrective measures for these vulnerabilities.


How to Report

Security vulnerabilities in current or previous product versions should be reported to Prologa via our designated contact address: security@prologa.com. Throughout the entire vulnerability disclosure process, the Prologa Product Security Response Team serves as the central coordination point for communication regarding reported security vulnerabilities.


Prologa Vulnerability Disclosure Process

The Prologa Vulnerability Disclosure Process governs the receipt, validation, assessment, remediation, coordination, communication with customers, and disclosure of reported vulnerabilities. In this document, references to the vulnerability disclosure process encompass all activities related to the handling and coordinated disclosure of reported vulnerabilities.


The Vulnerability Disclosure Process includes the following activities:

1. Receipt of the vulnerability report.

2. Review and validation of the reported issue.

3. Assessment of potential impact and severity.

4. Coordination of remediation measures with the responsible development teams.

5. Creation and publication of customer advisories, including Prologa security advisories.

6. Coordinated public disclosure once mitigations are available.

Prologa welcomes the submission of information regarding security vulnerabilities, but our primary concern must be the security and integrity of our customers, as well as their business processes and practices. Therefore, Prologa uses the security vulnerability disclosure process to ensure that security vulnerabilities and their associated impacts are treated confidentially until mitigations are available and customers have had sufficient time to implement them.

The process of addressing security vulnerabilities can be complex and requires careful development, testing, and deployment of solutions that enhance the security and resilience of the system. When a security vulnerability is reported, a coordinator (or case manager) is appointed to coordinate communication between the reporter and the teams involved in addressing the issue and publishing the results. With the reporter’s consent, acknowledgments for discovering and reporting the vulnerability are typically included when the findings are published. The Product Security Response Team does not issue acknowledgments if the researcher disclosed the issue prior to the release of the patch.

Deploying patches is generally more complicated than a software upgrade on a home user’s PC. Depending on the nature and complexity of the vulnerability, patch deployment may require manual configurations and/or “downtime” in addition to an automated update. Due to these additional complications, some of our customers have regular patching cycles, such as monthly or quarterly.

In light of these circumstances, Prologa asks security researchers to allow customers sufficient time to implement patches on their systems. As a rule of thumb, Prologa recommends observing a three-month implementation period following the release of the patch and asks all security researchers to refrain from disseminating any information or tools that could be used to exploit the vulnerability during this time. Please inform the Product Security Response Team of any planned publications, public security advisories, and external presentations that disclose security information regarding Prologa products.


Our Commitment (SLA)

Acknowledgment: We will acknowledge receipt of your report within 3 business days.

Review: We will investigate the report and notify you of the review status within 10 business days.

Updates: We will keep you regularly informed of the current status.


Safe Harbor & Authorization

Prologa understands that researchers wish to receive recognition for their work, which includes the publication and presentation of their findings. This policy is intended to allow Prologa to provide technical feedback to ensure accuracy and to prevent SAP customers from being exposed to unnecessary risks due to premature disclosure or insufficient information to protect their systems.

We guarantee that we will not take any legal action against you as long as you act in good faith and adhere to the following rules:

  • do not carry out attacks that could lead to a service interruption (DoS/DDoS).
  • do not exploit the security vulnerability beyond what is strictly necessary to prove its existence (e.g., do not copy, modify, or delete any data).
  • refrain from social engineering attacks (phishing), spam, or physical security attacks against our employees or data centers.
  • treat all information regarding the security vulnerability as strictly confidential until a solution is released.

This security vulnerability disclosure policy is publicly available on our website.


Deutsche Version

Die Sicherheit unserer Systeme und der Schutz von Daten haben für uns oberste Priorität. Trotz sorgfältiger Absicherung kann es vorkommen, dass Sicherheitslücken übersehen werden. Wenn Sie eine Schwachstelle in unseren Systemen oder Diensten gefunden haben, möchten wir Sie bitten, uns dies auf koordinierte Weise mitzuteilen.


Geltungsbereich

Diese Richtlinie zur Offenlegung von Sicherheitslücken definiert den Prozess, über den Sicherheitsforscher und andere Parteien potenzielle Schwachstellen in Prologa-Produkten melden können. Ziel ist es, Prologa in die Lage zu versetzen, Schwachstellen auf koordinierte Weise zu untersuchen, zu bewerten, zu beheben und zu kommunizieren, bevor detaillierte Informationen zu diesen Schwachstellen öffentlich bekannt werden.

Nicht im Geltungsbereich: IT-Systeme von Drittanbietern oder Partnern, die mit uns verknüpft sind.


Ansprechpartner

Das Prologa Product Security Response Team ist dafür verantwortlich, alle gemeldeten Sicherheitslücken zu untersuchen, eng mit den Meldenden und der Prologa-Produktentwicklung zusammenzuarbeiten, um diese Sicherheitslücken zu beheben, und Kunden darüber zu informieren, wie sie die Korrekturmaßnahmen für diese Sicherheitslücken umsetzen können.


So melden Sie

Sicherheitslücken in aktuellen oder früheren Produktversionen sollten Prologa über unsere dafür vorgesehene Kontaktadresse gemeldet werden: security@prologa.com. Während des gesamten Prozesses zur Offenlegung von Sicherheitslücken fungiert das Prologa Product Security Response Team als zentrale Koordinationsstelle für die Kommunikation im Zusammenhang mit gemeldeten Sicherheitslücken.


Prologa-Prozess zur Offenlegung von Sicherheitslücken

Der Prologa-Prozess zur Offenlegung von Sicherheitslücken regelt den Empfang, die Validierung, die Bewertung, die Behebung, die Koordination, die Kommunikation mit den Kunden und die Offenlegung gemeldeter Sicherheitslücken. In diesem Dokument umfassen Verweise auf den Prozess zur Offenlegung von Sicherheitslücken alle Aktivitäten im Zusammenhang mit der Bearbeitung und der koordinierten Offenlegung gemeldeter Sicherheitslücken.


Der Prozess zur Offenlegung von Sicherheitslücken umfasst die folgenden Aktivitäten:

1. Entgegennahme des Sicherheitslückenberichts.

2. Überprüfung und Validierung des gemeldeten Problems.

3. Bewertung der potenziellen Auswirkungen und des Schweregrads.

4. Koordination der Behebungsmaßnahmen mit den zuständigen Entwicklungsteams.

5. Erstellung und Veröffentlichung von Kundenhinweisen, einschließlich der Prologa-Sicherheitshinweise.

6. Koordinierte öffentliche Bekanntgabe nach Verfügbarkeit von Abhilfemaßnahmen.

Prologa begrüßt die Übermittlung von Informationen zu Sicherheitslücken, doch unser Hauptanliegen muss die Sicherheit und Integrität unserer Kunden sowie ihrer Geschäftsprozesse und -praktiken sein. Daher nutzt Prologa den Prozess zur Offenlegung von Sicherheitslücken, um sicherzustellen, dass Sicherheitslücken und die damit verbundenen Auswirkungen vertraulich behandelt werden, bis Abhilfemaßnahmen verfügbar sind und die Kunden ausreichend Zeit hatten, diese zu implementieren.

Der Prozess zur Behebung von Sicherheitslücken kann komplex sein und erfordert eine sorgfältige Entwicklung, Tests und die Einführung von Lösungen, die die Sicherheit und Ausfallsicherheit des Systems verbessern. Wird eine Sicherheitslücke gemeldet, wird ein Koordinator (oder Fallverantwortlicher) benannt, der die Kommunikation zwischen dem Melder und den Teams koordiniert, die an der Behebung und der Veröffentlichung der Ergebnisse beteiligt sind. Mit der Zustimmung des Melders werden bei der Veröffentlichung der Ergebnisse in der Regel Danksagungen für das Aufdecken und Melden der Sicherheitslücke aufgeführt. Das Product Security Response Team spricht keine Danksagungen aus, wenn der Forscher das Problem vor der Veröffentlichung des Patches offengelegt hat.

Die Bereitstellung von Patches ist in der Regel komplizierter als ein Software-Upgrade auf einem Privatkunden-PC. Je nach Art und Komplexität der Sicherheitslücke kann die Bereitstellung von Patches neben einem automatisierten Update auch manuelle Konfigurationen und/oder „Ausfallzeiten“ erfordern. Aufgrund dieser zusätzlichen Komplikationen haben einige unserer Kunden regelmäßige Patching-Zyklen, beispielsweise monatlich oder vierteljährlich.

Angesichts dieser Umstände bittet Prologa Sicherheitsforscher darum, den Kunden ausreichend Zeit für die Implementierung von Patches in ihren Systemen einzuräumen. Als Faustregel empfiehlt Prologa, nach der Veröffentlichung des Patches eine Implementierungsfrist von drei Monaten einzuhalten, und bittet alle Sicherheitsforscher, während dieser Zeit keinerlei Informationen oder Tools zu verbreiten, die zur Ausnutzung der Sicherheitslücke dienen könnten. Bitte informieren Sie das Product Security Response Team über geplante Veröffentlichungen, öffentliche Sicherheitshinweise und externe Präsentationen, in denen Sicherheitsinhalte zu Prologa-Produkten verbreitet werden.


Unsere Verpflichtung (SLA)

Bestätigung: Wir bestätigen den Eingang Ihres Berichts innerhalb von 3 Werktagen.

Überprüfung: Wir untersuchen den Bericht und teilen Ihnen den Überprüfungsstatus innerhalb von 10 Werktagen mit.

Aktualisierungen: Wir informieren Sie regelmäßig über den aktuellen Stand.


Safe Harbor & Autorisierung

Prologa hat Verständnis dafür, dass Forscher Anerkennung für ihre Arbeit erhalten möchten, wozu auch die Veröffentlichung und Präsentation ihrer Ergebnisse gehört. Diese Richtlinie dient dazu, dass Prologa technisches Feedback geben kann, um die Richtigkeit sicherzustellen und zu vermeiden, dass Prologa-Kunden durch vorzeitige Offenlegung oder unzureichende Informationen zum Schutz ihrer Systeme unnötigen Risiken ausgesetzt werden.

Wir garantieren, dass wir keine rechtlichen Schritte gegen Sie einleiten werden, solange Sie in gutem Glauben handeln und sich an die folgenden Regeln halten:

  • führen keine Angriffe durch, die zu einer Dienstunterbrechung führen könnten (DoS/DDoS).
  • die Sicherheitslücke nicht weiter ausnutzen, als es zum Nachweis ihrer Existenz unbedingt erforderlich ist (z. B. keine Daten kopieren, ändern oder löschen).
  • auf Social-Engineering-Angriffe (Phishing), Spam oder physische Sicherheitsangriffe gegen unsere Mitarbeiter oder Rechenzentren verzichten.
  • alle Informationen bezüglich der Sicherheitslücke streng vertraulich behandeln, bis eine Lösung veröffentlicht wird.

Diese Richtlinie zur Offenlegung von Sicherheitslücken ist auf unserer Website öffentlich zugänglich.

Trusted by industry leaders

Our partnerships with SAP, Microsoft, and leading enterprises validate our commitment to innovation

Do you still have any questions?

We’d love to hear from you! Get in touch with us directly and we’ll answer all your questions and keep you updated.