CVE-2024-22319
high · 8.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
8.1
CVSS
76.4%
EPSS (exploit prob.)
100th
EPSS percentile
2024-02-02
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-74
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | operational_decision_manager | 8.10.3 |
| ibm | operational_decision_manager | 8.10.4 |
| ibm | operational_decision_manager | 8.10.5.1 |
| ibm | operational_decision_manager | 8.11 |
| ibm | operational_decision_manager | 8.11.0.1 |
| ibm | operational_decision_manager | 8.12.0.1 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-22319