peter bassill · operator
$ cve CVE-2018-20221 JSON

CVE-2018-20221 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 10.3% (pctl 96)

Patch early

A public exploit exists.

Description

Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS10.27% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploityes
Published2019-03-21
Last modified2026-06-17

Affected (1)

VendorProduct
deltekajera

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD