With Oracle claiming it's not their problem to fix, and with the mobile networking industry generally being slow and old-fashioned, I'm surprised they even offered a bounty and worked with them for public disclosure rather than threatening to sue.
$30k is a pittance for the work put in if you were to negotiate with them as contractors, but it's still a good chunk of change for essentially unprompted, free work. They didn't need to pay them a dime, after all.
I’ve been pretty disappointed with the seemingly small payouts some of the bug bounties I’ve seen submitted were / are getting.
It’s like the companies “forgot” [1] what happens when you don’t have a bug bounty program or what happens when people step to others with their bugs.
1. of course companies didnt forget, this is the benefit of the doubt I like to give but big companies like this aren’t stupid.
Big companies are ruled by the business savvy but less technical and those see things like the bug bounty program as not important, until they get shook awake by a huge breach or anything of the sort that impacts the stock price ( their salary ) I doubt they will care much.