Deltek's vulnerability footprint centers on a narrow portfolio of enterprise project-management and financial-software products including Ajera, Maconomy, and Vision, which are deployed in professional-services and government-contracting environments. The recurring signal is rooted in application-layer handling of untrusted input and configuration data, with observed weaknesses spanning deserialization flaws, path traversal, SQL injection, and hard-coded credentials—patterns typical of business software that processes and stores structured data from multiple sources. Current severity, exploitation status, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deltek over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12314CRITICAL Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/et | May 24, 2019 | 9.8 | 88 | NO | YES |
CVE-2018-20221HIGH Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. Th | Mar 21, 2019 | 8.8 | 40 | NO | YES |
CVE-2018-18251CRITICAL Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to | Apr 24, 2019 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deltek.
Media articles that mention a CVE ID that affects a product developed by Deltek — matched by CVE ID, not by vendor name.