CVE-2018-20221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
21/03/2019
Last modified:
17/06/2026

Description

Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:deltek:ajera:*:*:*:*:*:*:*:* 9.10.16 (including)