Vulnerabilities > Deltek

DATE CVE VULNERABILITY TITLE RISK
2019-05-24 CVE-2019-12314 Path Traversal vulnerability in Deltek Maconomy 2.2.5
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI.
network
low complexity
deltek CWE-22
critical
9.8
2019-04-24 CVE-2018-18251 Use of Hard-coded Credentials vulnerability in Deltek Vision 7.0/7.1
Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol.
network
low complexity
deltek CWE-798
critical
9.8
2019-03-21 CVE-2018-20221 Deserialization of Untrusted Data vulnerability in Deltek Ajera
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user.
network
low complexity
deltek CWE-502
8.8