Matera is a niche banking and financial services software vendor whose vulnerability footprint centers on its Banco product line, which serves as a core platform for payment processing and account management. Vulnerabilities affecting the vendor skew toward serious outcomes and recur across application-layer weakness classes including cross-site scripting, cross-site request forgery, path traversal, and information disclosure flaws that are characteristic of web-facing financial platforms where input validation and access control are critical. Defenders managing Banco deployments should prioritize patching and conduct input-handling and session-management reviews; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matera over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14925CRITICAL Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components. | Aug 3, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14926HIGH Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request. | Aug 3, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-14928HIGH /contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter. | Aug 3, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14929MEDIUM Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter. | Aug 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14924MEDIUM Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field. | Aug 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14927MEDIUM Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application folder) via the /contingency/servlet/ServletFileDownload file pa | Aug 3, 2018 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matera.
Media articles that mention a CVE ID that affects a product developed by Matera — matched by CVE ID, not by vendor name.