CVE-2024-22319

HIGH EXPLOITED NUCLEI

IBM Operational Decision Manager - JNDI Injection

Title source: nuclei

Description

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

Nuclei Templates (1)

IBM Operational Decision Manager - JNDI Injection
CRITICALVERIFIEDby DhiyaneshDK
Shodan: html:"IBM ODM" || http.html:"ibm odm"
FOFA: title="IBM ODM" || title="ibm odm" || body="ibm odm"

Scores

CVSS v3 8.1
EPSS 0.8699
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-03-17
CWE
CWE-74
Status published
Products (6)
ibm/operational_decision_manager 8.10.3
ibm/operational_decision_manager 8.10.4
ibm/operational_decision_manager 8.10.5.1
ibm/operational_decision_manager 8.11
ibm/operational_decision_manager 8.11.0.1
ibm/operational_decision_manager 8.12.0.1
Published Feb 02, 2024
Tracked Since Feb 18, 2026