CVE-2024-22319
IBM Operational Decision Manager JDNI injection
Record summary
CVE-2024-22319 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.
Description
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 17, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Operational Decision ManagerBrowse IBM / Operational Decision ManagerDefault status: unaffected, unknown | CVE List, VulnCheck | 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1, 8.12.0.1 | affected |
| 8.10.3 | affected | ||
| 8.10.4 | affected | ||
| 8.10.5.1 | affected | ||
| 8.11 | affected | ||
| 8.11.0.1 | affected | ||
| 8.11.1 | affected | ||
| 8.12.0.1 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALIBM Operational Decision Manager - JNDI InjectionCVSS 9.8
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
Impact
Unauthenticated attackers can execute arbitrary code via JNDI injection, potentially compromising the entire IBM ODM system.
Remediation
Update IBM Operational Decision Manager to a version that addresses CVE-2024-22319.
Source: ProjectDiscovery