it is not that the apps themselves use Heartbleed, but they communicate to back-office servers that provide information such as transaction history that might not have been included in a Heartbleed scan.In addition, other types of servers throughout a bank's data center could be susceptible.The back office infrastructure this is calling into question is not only web servers, it could be FTP server