---
id: CVE-2018-16497
title: >-
  In Versa Analytics, the cron jobs are used for scheduling tasks by executing
  commands at specific dates and times on the server
summary: >-
  In Versa Analytics, the cron jobs are used for scheduling tasks by executing
  commands at specific dates and times on the server. If the job is run as the
  user root, there is a potential privilege escalation vulnerability. In this
  case, t…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
  - CWE-269
vendor: versa-networks
product: versa_analytics
affected:
  - versa_analytics < 16.1R2S11
  - 'versa_analytics >= 20.2.0, < 20.2.2'
  - 'versa_analytics >= 21.1.0, < 21.1.1'
  - 'versa_analytics >= 21.2.0, < 21.2.1'
patched:
  - versa_analytics 21.2.1
published: '2021-05-26'
updated: '2026-08-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-16497'
references:
  - url: 'https://hackerone.com/reports/1168194'
    label: support@hackerone.com
  - url: 'https://hackerone.com/reports/1168194'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00228
epssPercentile: 0.1379
ingestedAt: '2026-08-31T18:12:23.475Z'
---

## Overview

In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, the job runs a script as root that is writable by users who are members of the versa group.

## Affected

- `versa_analytics < 16.1R2S11`
- `versa_analytics >= 20.2.0, < 20.2.2`
- `versa_analytics >= 21.1.0, < 21.1.1`
- `versa_analytics >= 21.2.0, < 21.2.1`

## Remediation

Upgrade past the affected range:

- `versa_analytics 21.2.1`
