CVE-2018-18251
Last modified
CVE-2018-18251 is a vulnerability of currently unknown severity. Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server. Client HTTP calls can be manipulated by one of several means to execute arbitrary SQL statements (similar to SQLi) or possibly have unspecified other impact via this custom protocol. To perform these attacks an authenticated session is first required. In some cases client calls are obfuscated by encryption, which can be bypassed due to hard-coded keys and an insecure key rotation protocol. Impacts may include remote code execution in some deployments; however, the vendor states that this cannot occur when the installation documentation is heeded.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Deltek | Vision | >= 7.0, < 7.6 |
References
- https://www.vsecurity.com/resources/advisories.htmlThird Party Advisory
- https://www.vsecurity.com/resources/advisories.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18251?
How severe is CVE-2018-18251?
How do I fix CVE-2018-18251?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-18246Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/mo…
- CVE-2018-18247Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/naviga…
- CVE-2018-18248Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/ser…
- CVE-2018-18249Icinga Web 2 before 2.6.2 allows injection of PHP ini-file d…
- CVE-2018-1825IBM Rational Quality Manager 5.0 through 6.0.6 is vulnerable…5.4
- CVE-2018-18250Icinga Web 2 before 2.6.2 allows parameters that break navig…
- CVE-2018-18252An issue was discovered in CapMon Access Manager 5.4.1.1005.…
- CVE-2018-18253An issue was discovered in CapMon Access Manager 5.4.1.1005.…
- CVE-2018-18254An issue was discovered in CapMon Access Manager 5.4.1.1005.…
- CVE-2018-18255An issue was discovered in CapMon Access Manager 5.4.1.1005.…
- CVE-2018-18256An issue was discovered in CapMon Access Manager 5.4.1.1005.…
- CVE-2018-18257An issue was discovered in BageCMS 3.1.3. An attacker can de…
Are you affected by CVE-2018-18251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
