IBM Operational Decision Manager JDNI injection
CVE-2024-22319
8.1HIGH
Summary
IBM Operational Decision Manager is vulnerable to remote code execution attacks due to a JNDI injection flaw. The vulnerability arises when an unchecked argument is passed to a specific API, allowing an attacker to execute arbitrary code remotely. This poses a serious risk as it could enable unauthorized access to sensitive data or control over the affected system. Multiple versions of the product are impacted, making it critical for users to address this vulnerability promptly.
Affected Version(s)
Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1, 8.12.0.1
References
EPSS Score
54% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database