CVE-2018-20221 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 10.3% (pctl 96)
Patch early
A public exploit exists.
Description
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 10.27% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-03-21 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| deltek | ajera |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data | 2019-01-07 |
References
→ the Explorer · watch your stack · NVD