Responsible Disclosure

At the Austrian National Bank we value the support of IT security researchers and members of cybersecurity communities who help us maintain our high IT security standards.

If you identify an IT security vulnerability relating to one of our websites, please notify us promptly before disclosing it to any third party, so that we can take the necessary measures. Please keep all information relating to the discovered vulnerability secret from all third parties for a period of at least 90 days.

Scope:

Other sites, as well as subdomains of the sites listed above, are currently not included within this scope.

How to notify us

Send your report as soon as possible by email to disclosure@oenb.at. Please use the provided PGP key to protect the information.

Please include:

  • your contact details (name, email address and PGP key);
  • the type of vulnerability identified;
  • the affected service/device/application;
  • a detailed description of the problem;
  • the IP address(es) from which the vulnerability was identified, together with the date and time of discovery;
  • a compressed archive (ZIP) with files that help reproduce the flaw (e.g. screenshots, PoC, source code, scripts, pcap traces, logs).

Acting responsibly – not a permission to attack
Please act responsibly in dealing with your discovery. Do not take any action beyond what is needed to identify and verify the issue. Do not use the vulnerability to your own advantage, and do not store any confidential data obtained as a result of the issue.

This policy does not constitute a permission to attack. It does not authorise active security or penetration testing, attacks, or any other interference against our systems, websites or infrastructure. In particular, actions that could affect the availability, integrity or confidentiality of our services, such as denial-of-service attacks, automated exploitation of vulnerabilities, or accessing, altering or deleting data, are not permitted. This policy provides no legal assurance to refrain from criminal or civil prosecution and does not exempt you from complying with applicable law.

Vulnerabilities we will consider
Injection and deserialization vulnerabilities (SQL/NoSQL/LDAP injection, command injection, object deserialization); broken authentication and access control; sensitive data exposure; cross-site scripting; cross-site request forgery; XML external entities (XXE); server-side request forgery (SSRF); redirect vulnerabilities; underprotected APIs; known and zero-day vulnerabilities.

Vulnerabilities we will not consider
Unless they lead to actual exploitation: weak TLS configurations; non-compliance with best practices (e.g. SPF/DKIM/DMARC, content security policy, TLS misconfigurations); output of well-known automated tools.

How we will respond
We will confirm receipt of your report within two business days and send our assessment, including the expected resolution date, within five business days of that confirmation. We will treat your report as confidential and will not share your details with third parties except where obliged to do so by law. We are currently not running a reward programme.