Security Vulnerability Disclosure
We take the security of the MyID product suite seriously. If you believe you have found a security vulnerability in any of our products, we want to hear from you, and we will work with you to verify and resolve it responsibly.
How to Report
If you have discovered a vulnerability with any of our products, please email security.notifications@intercede.com with the information described below, in accordance with our Security Disclosure Policy.
Information to include in your report
Items marked (M) are mandatory. The more detail you can provide, the faster we can verify and address the issue.
| Field | What to provide |
|---|---|
| Title (M) | A concise summary categorising the vulnerability. |
| Product (M) | Name and version of the product affected. |
| Weakness | Based on the Common Weakness Enumeration (CWE). |
| Severity | Such as low, medium, high or critical, calculated via the NIST Common Vulnerability Scoring System (CVSS) calculator. |
| Description of the vulnerability (M) | What the vulnerability is and its impact. Include support files (e.g. screenshot or video) and any mitigations or recommendations. |
| Steps to reproduce / impact | Clear, descriptive steps to reproduce the vulnerability, and the effect(s) of successfully exploiting it. |
| Contact details | Name, email address, organisation and phone number. These details are optional, to allow anonymous reporting. |