← All CVEs

CVE-2024-22320

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

9.8
CVSS
73.4%
EPSS (exploit prob.)
99th
EPSS percentile
2024-02-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
ibmoperational_decision_manager8.10.3
ibmoperational_decision_manager8.10.4
ibmoperational_decision_manager8.10.5.1
ibmoperational_decision_manager8.11
ibmoperational_decision_manager8.11.0.1
ibmoperational_decision_manager8.12.0.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-22320