I don't have any ill feelings against the bank or the management, it's just a stupid setup where the local prophet gets ignored, we are swamped with bugs, new business features, new regulatory features, outdated devops, a lot of teams scrambling to catch the monthly release, understaffed qa, non-functional test environments and so on.
I can understand every piece of the long string of factors that lead to this ridiculous situation where such a serious security issue is not being addressed; any one in particular is not ridiculous, but they all compound to the ridiculous of the end result.
I've fixed another ridiculous security issue in the recent past without making big waves, where only one software architect understood the seriousness of just one option in a maven config file(a whole declarative security module was not being weaved into the bytecode because somone added another module and instead of both being applied, only the most recent one was being applied).