IOM Responsible Vulnerability Disclosure Program (VDP) 

To improve the protection of its Information and Communication Technologies (ICT) systems and assets, IOM encourages the public to assist with its efforts by disclosing vulnerabilities in IOM’s publicly accessible information systems and assets as well as reporting cybersecurity issues. 

What to Report to IOM 

The public is invited to report cybersecurity issues, incidents, and details of vulnerabilities associated with publicly accessible IOM ICT systems, including websites. 

Information on Vulnerability Reporting 

The following should be noted when reporting vulnerabilities and cybersecurity issues and incidents to IOM: 

  • The vulnerability and/or cybersecurity issue or incident should not already be publicly disclosed. 

  • The vulnerability and/or cybersecurity issue or incident should be reported to IOM as quickly as possible after its discovery. 

  • The reporter is expected to keep the vulnerability findings confidential for at least 90 days following the date the vulnerability or cybersecurity issue or incident was reported to IOM or until public disclosure of the vulnerability has been made on this website. 

  • The severity of a vulnerability finding is assessed by IOM at its own discretion. 

  • The name and contact information of the reporter may be disclosed to the affected technology vendor(s) unless otherwise requested by the reporter. · IOM reserves the right to accept or reject any security vulnerability or cybersecurity issue, or incident disclosure report at its discretion. 

If you believe you have found a vulnerability or issue and would like to report it, we ask that you submit a detailed description of the issue to us, including the steps that we can take to reproduce the issue and/or a proof-of-concept: 

As much information as possible regarding the finding should be communicated to IOM to enable the organization to reproduce and verify the vulnerability, issue, or incident to implement appropriate remediation actions. 

Once you submit a report to IOM, please allow the information security team a reasonable amount of time to respond to your report and correct the issue. 

If more information is required regarding a reported finding, IOM may contact the reporter; therefore, it is important to provide valid contact details, including email address and/or telephone number. 

Upon receipt of the report, IOM will verify the existence of the vulnerability, notify affected parties, and implement actions to mitigate the vulnerability. 

Once the vulnerability has been removed, the reporter will be acknowledged unless he/she wishes to remain anonymous and listed (at his or her own discretion) on this page with a short description of the vulnerability reported. By reporting vulnerability findings to the IOM, the reporter accepts that such reporting is provided pro bono and without expectation of financial or other compensation. The reporter also affirms that neither he/she nor any entity that he/she represents is complicit in human rights abuses, tolerates forced or compulsory labour or uses child labour, is involved in the sale or manufacture of anti-personnel mines or their components, or does not meet the purposes and principles of the United Nations. 

IOM Information Security Hall of Fame 

IOM is grateful to the following individuals and organizations that have helped the Organization to improve the security of its information systems, data, and ICT resources by reporting security issues and discovered vulnerabilities.

Reporter 

Cyber Security Issue 

Date 

Saeed Jaber - Abugosh User passwords detected in dark web 20 October 2021
Gaurang Maheta Reported OpenSSH vulnerability 22 July 2021

Gaurang Maheta 

SMB-v1 detection 

01 July 2021 

Gaurang Maheta 

Reported XML-RPC vulnerability 

13 June 2021