Powered by: Allows bounty splitting:
Average time to first program response: 9
Average time to bounty awarded null:
Average time to report resolved: 199
Handle mendix
Managed program: true
Name: Mendix
Offers bounties: false
Offers swag: false
Response efficiency percentage: 100
Submission state: open
Url: https://hackerone.com/mendix
Website: https://mendix.com
In scope: Asset identifier: *.mendix.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: # *.mendix.com
This is an open-ended program, we want to be better and we welcome your help us get there.
## Observations
- Some of the sub-domains are behind sign-up
- The CIA impact will vary depending on the explored vulnerabilities.Integrity requirements: highMax severity: criticalAsset identifier: *.timeseries.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: highMax severity: criticalAsset identifier: *.timeseries.nlAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: highMax severity: criticalAsset identifier: 3dvis.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: #3dvis.mendixcloud.com
3dviewer production environmentIntegrity requirements: highMax severity: criticalAsset identifier: 3s.mendixcloud.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://3s.mendixcloud.comIntegrity requirements: Max severity: criticalAsset identifier: alm.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://alm.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: contributor.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: #contributor.mendixcloud.com
This is a frontend application for onboarding flow in Marketplace.
## Endpoints
- URL: https://contributor.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: datalake-sync.apps.mendix.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://datalake-sync.apps.mendix.comIntegrity requirements: highMax severity: criticalAsset identifier: dataprivacy.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://dataprivacy.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: dealservice.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://dealservice.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: deskallocation.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://deskallocation.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: employees.mendix.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://employees.mendix.comIntegrity requirements: highMax severity: criticalAsset identifier: event.us-east-1.sws.siemens.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: # Event Notification Service
This one is one of our forthcoming applications and we would like your help to check it out!
## Endpoints
- App's URL: https://event.us-east-1.sws.siemens.com/Integrity requirements: highMax severity: criticalAsset identifier: gateway.us-east-1.sws.siemens.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: # Authorization information:
Endpoint : gateway.us-east-1.sws.siemens.com
- samAccessKeyId : 3491d6d93e82498e828d468ebce592f0
- samSecretAccessKey : gAgnBmdPGnlOtX/I0CoY7aIJVoU95lkJ7DorNXI1SBk=Integrity requirements: highMax severity: criticalAsset identifier: https://react.vis.pre2.usea1.devops.sws.siemens.com/sample/dist/index.htmlAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: 3dviewer dev/testing environmentIntegrity requirements: highMax severity: criticalAsset identifier: k8s-licbrk-licenseb-11d216e80e-384217420.eu-central-1.elb.amazonaws.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: license broker
url:
k8s-licbrk-licenseb-11d216e80e-384217420.eu-central-1.elb.amazonaws.comIntegrity requirements: Max severity: criticalAsset identifier: marketplaceadmin.mendixcloud.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: mxbpconfig.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: # Visualisation Platform
This application is used for Mendix Basic Package configuration.
## Endpoints
- App's URL: https://mxbpconfig.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: mxpeople.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://mxpeople.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: notification.billing.appservices.mendix.com/Asset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: o0pv3l7chl.execute-api.us-east-1.amazonaws.com/devAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: # o0pv3l7chl.execute-api.us-east-1.amazonaws.com/dev
Please use the following credential when testing this endpoint:
- x-api-key (authentication header): ZLHxyM4kfB6jPdoAwDStfJJn8k3zOofawN9VpZy3Integrity requirements: highMax severity: criticalAsset identifier: poh0v3odoi.execute-api.eu-central-1.amazonaws.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: highMax severity: criticalAsset identifier: provisioning.servicemanagement.mendix.comAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: revenuedatahub.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://revenuedatahub.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: servicemanagement-accp.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: highMax severity: criticalAsset identifier: simplate.mendixcloud.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: ## Endpoints
- URL: https://simplate.mendixcloud.comIntegrity requirements: highMax severity: criticalAsset identifier: slm.store.mendix.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: #slm.appservices.mendix.com
AppService Lifecycle service
## Endpoints
- URL: https://slm.store.mendix.comIntegrity requirements: highMax severity: critical