Record summary

CVE-2024-22319 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.

Description

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 17, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Operational Decision Manager

Browse IBM / Operational Decision Manager

Default status: unaffected, unknown

CVE List, VulnCheck8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1, 8.12.0.1affected
8.10.3affected
8.10.4affected
8.10.5.1affected
8.11affected
8.11.0.1affected
8.11.1affected
8.12.0.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALIBM Operational Decision Manager - JNDI InjectionCVSS 9.8

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

Impact

Unauthenticated attackers can execute arbitrary code via JNDI injection, potentially compromising the entire IBM ODM system.

Remediation

Update IBM Operational Decision Manager to a version that addresses CVE-2024-22319.

WeaknessesCWE-74
AuthorsDhiyaneshDK
Template tagscvecve2024ibmodmdecision-managerjndijsfrcevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ibm:operational_decision_manager:8.10.3:*:*:*:*:*:*:*
Shodan: html:"IBM ODM"
Shodan: http.html:"ibm odm"
FOFA: title="IBM ODM"
FOFA: title="ibm odm"
FOFA: body="ibm odm"

Source: ProjectDiscovery

References

3