PoC Index

CVE-2018-20221

HIGH 8.8EPSS 10.3%

Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
10.27% chance of exploitation in the next 30 days, 95th percentile
Published
2019-03-17
Updated
2024-08-05

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related