IBM Operational Decision Manager JDNI injection
CVE-2024-22319

8.1HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 February 2024

Summary

IBM Operational Decision Manager is vulnerable to remote code execution attacks due to a JNDI injection flaw. The vulnerability arises when an unchecked argument is passed to a specific API, allowing an attacker to execute arbitrary code remotely. This poses a serious risk as it could enable unauthorized access to sensitive data or control over the affected system. Multiple versions of the product are impacted, making it critical for users to address this vulnerability promptly.

Affected Version(s)

Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1, 8.12.0.1

References

EPSS Score

54% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.