CVE-2018-20221
Last modified
CVE-2018-20221 is a vulnerability of currently unknown severity. Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.. EPSS estimates a 10.46% chance of exploitation in the next 30 days.
Description
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Deltek | Ajera | <= 9.10.16 |
References
- http://packetstormsecurity.com/files/151035/Ajera-Timesheets-9.10.16-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46086/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/151035/Ajera-Timesheets-9.10.16-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/46086/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20221?
How severe is CVE-2018-20221?
How do I fix CVE-2018-20221?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20216QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_rin…7.5
- CVE-2018-20217A Reachable Assertion issue was discovered in the KDC in MIT…5.3
- CVE-2018-20218An issue was discovered on Teracue ENC-400 devices with firm…
- CVE-2018-20219An issue was discovered on Teracue ENC-400 devices with firm…
- CVE-2018-2022IBM QRadar SIEM 7.2 and 7.3 discloses sensitive information …5.3
- CVE-2018-20220An issue was discovered on Teracue ENC-400 devices with firm…
- CVE-2018-20222XXE issue in Airsonic before 10.1.2 during parse.
- CVE-2018-20225An issue was discovered in pip (all versions) because it ins…7.8
- CVE-2018-20226An organization administrator can add a super administrator …
- CVE-2018-20227RDF4J 2.4.2 allows Directory Traversal via ../ in an entry i…7.5
- CVE-2018-20228Subsonic V6.1.5 allows internetRadioSettings.view streamUrl …
- CVE-2018-20229GitLab Community and Enterprise Edition before 11.3.14, 11.4…
Are you affected by CVE-2018-20221?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
