This document describes the timeframes that we try our best to follow, while fixing security vulnerabilities.

Please note that these timeframes do not constitute as SLAs but rather targets we set for planning our work.

This is v1 of the document dated 28 July 2020

Targets for Fixing Security Vulnerabilities

Security vulnerabilites should be fixed in the timeframes below, starting when the vulnerability is reported and confirmed.


SeverityCloud AppsServer & Data Center Apps
Critical2 weeks4 weeks
High4 weeks12 weeks
Medium8 weeks18 weeks
Low26 weeks26 weeks


For details on vulnerability classification, see Severity Levels for Security Issues.

  • No labels