Security Advisories
Responsible disclosure of security vulnerabilities.
What does Security Advisories mean?
Nearly every information system has errors. These errors are being discovered throughout the lifespan of a system. If these errors affect the confidentiality, integrity or availability of a system, they are called security vulnerabilities.
Vulnerabilities found by the aramido GmbH are disclosed in a responsible way to the public according to the following procedure. Vulnerabilities for which customers of aramido are responsible or which are otherwise legally excluded from publication are not disclosed according to this policy.
After a security vulnerability is discovered, the responsible parties for the system or the application are informed in a confidential manner. The security advisory describes the type and exploitability of the vulnerability. The security advisory will be published after the vulnerability is patched or at least after 45 days after the first notice, regardless of the remediation level, on the aramido website. Exceptions to this process are only made in well justified cases and after considering the impact on the public.
Vulnerabilities found by aramido could have already been discovered and exploited by others. Therefore, vulnerabilities should immediately be patched. It is the social responsibility of aramido to protect the public and disclose vulnerabilities. This way vulnerabilities get fixed, everyone can learn from past mistakes and adjust his or her behavior.



