Security

Overview

This page outlines the process for reporting security issues in Bloomreach products, describes how Bloomreach addresses security vulnerabilities, and explains how to keep your Bloomreach Content implementation current with security updates.

Reporting a Security Issue

If you identify a potential security vulnerability in a Bloomreach product, contact xm-security@bloomreach.com immediately. This initiates the security response process described below.

Bloomreach Security Issue Handling Process

Bloomreach follows a defined process for managing security-related issues:

  1. Report Issue
    Report any potential security vulnerability by emailing xm-security@bloomreach.com. This address is monitored by product stakeholders from multiple departments.

  2. Assess Issue
    Product stakeholders review the report within one business day.

    • If the issue is determined to be a potential security vulnerability, it is logged in the internal issue tracking system and assigned to the appropriate team. The reporter is notified that the issue is under investigation.

    • If the issue is not security-related, the reporter receives a standard response and the issue is forwarded to the helpdesk for further assistance if needed.

  3. Verify Issue
    The assigned team verifies the reported behavior. The outcome—either verified or not reproducible—is communicated to the reporter.

  4. Fix Issue
    The team categorizes verified issues as major or minor. For major issues (those with an OWASP rating of MEDIUM or higher), a dedicated hotfix may be created if necessary. All fixes are included in the next regular maintenance release.

  5. Inform Customers
    All Bloomreach Content customers are notified about the security fix and are encouraged to apply the hotfix or maintenance release promptly.

  6. Inform Community
    The fix is included in the next maintenance release. Each resolved security issue is published on the security updates page to inform the Bloomreach Content community. After 24 months, maintenance releases become publicly available to the community. Once a major security fix is public, customers can upgrade to the latest maintenance release and remove any applied hotfix.

Staying Up-to-Date with Security Updates

Bloomreach Content customers receive direct notifications about new security updates and access to hotfixes. The Bloomreach Content community is informed of new security updates via the following pages and can upgrade to the latest maintenance release:

Security Policy for End-of-Life Libraries in Bloomreach Content

Bloomreach maintains a policy for managing end-of-life libraries and related backward-incompatible changes in Bloomreach Content:

  1. Major Version Updates for Incompatible Changes
    When end-of-life libraries require backward-incompatible changes, these are introduced in the next major version of Bloomreach Content. Minor version updates remain stable and backward compatible.

  2. Vulnerabilities in End-of-Life Libraries
    Some minor versions of Bloomreach Content may include end-of-life libraries that are no longer patched by third parties. This can expose those versions to unresolved vulnerabilities.

  3. Security Enhancements in Recent Major Versions
    The latest major versions of Bloomreach Content include security improvements and patches for vulnerabilities related to end-of-life libraries. Running older versions may expose your applications to security risks if they rely on unsupported dependencies. Updates that require backward-incompatible changes are only made in major releases.

  4. Importance of Upgrading
    Upgrading to the latest major version of Bloomreach Content is required to maintain security, reliability, and performance. Begin your upgrade planning as soon as possible to benefit from the latest security enhancements.

For questions or support during your upgrade process, contact Bloomreach support.

Share Feedback
Page: /about/open-source-community/security-procedure
Section: About
Category *