Fisglobal's vulnerability footprint is concentrated in a narrowly scoped but prominent product line, GT.M, a transaction processing and database platform deployed across financial services and mission-critical enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and arithmetic-handling demands inherent to a systems-level language runtime. The exposure recurs through weakness classes including NULL-pointer dereferences, improper input validation, buffer-boundary errors, incorrect calculations, and integer underflow conditions—a pattern typical of lower-level codebases where memory layout and numeric precision directly impact system stability. Defenders should treat this vendor's advisories as high-priority in environments where GT.M is deployed and prioritize patching to minimize the window of critical exposure. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fisglobal over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44496CRITICAL An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size variable and buffer that is passed to | Apr 15, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-44486CRITICAL An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value of a function pointer used in op_write in sr_port/op_write.c | Apr 15, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-44488CRITICAL An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and input to calls to memcpy in op_fnfnumber in sr_port/op_fnfnum | Apr 15, 2022 | 9.1 | 27 | NO | NO |
CVE-2021-44509HIGH An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memse | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44508HIGH An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to cras | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44502HIGH An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to u | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44494HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointe | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44492HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the fu | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44491HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-44490HIGH An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can cause a calculation of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c | Apr 15, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fisglobal.
Media articles that mention a CVE ID that affects a product developed by Fisglobal — matched by CVE ID, not by vendor name.