PT-2019-9560 · Deltek · Deltek Vision
Published
2019-04-24
·
Updated
2020-08-24
·
CVE-2018-18251
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Deltek Vision versions prior to 7.6
Description
The issue allows the execution of arbitrary SQL statements through a custom RPC over HTTP protocol. This is possible because the system relies on the client binary to enforce security rules and integrity of SQL statements. An attacker can manipulate client HTTP calls to execute arbitrary SQL statements, potentially having unspecified other impact. To perform these attacks, an authenticated session is required. In some cases, client calls are obfuscated by encryption, which can be bypassed due to hard-coded keys and an insecure key rotation protocol. The impact may include remote code execution in some deployments.
Recommendations
For Deltek Vision versions prior to 7.6, update to version 7.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the custom RPC over HTTP protocol to minimize the risk of exploitation. Additionally, ensure that the installation documentation is followed to prevent potential remote code execution.
Fix
Using Hardcoded Credentials
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deltek Vision