Fiserv develops financial services and payment processing software including reconciliation and banking platform products such as Accurate Reconciliation and Prologue, which serve as critical infrastructure in banking and transaction environments. The durable signal in its vulnerability profile centers on web application weaknesses including cross-site scripting and insufficiently protected credential handling, reflecting the web-facing and authentication-intensive nature of banking software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fiserv over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35992MEDIUM Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attr | Aug 23, 2022 | 6.5 | 23 | NO | NO |
CVE-2020-8952MEDIUM Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter. | Feb 26, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-8951MEDIUM Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) p | Feb 26, 2020 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fiserv.
Media articles that mention a CVE ID that affects a product developed by Fiserv — matched by CVE ID, not by vendor name.