← back
CVE-2018-20221

CVE-2018-20221

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 10%
from disclosure to weapon0 days
Published on NVDMar 17
1st PoCJan 7
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.