First published: Mon Jan 29 2024(Updated: )
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Operational Decision Manager | =8.10.3 | |
IBM Operational Decision Manager | =8.10.4 | |
IBM Operational Decision Manager | =8.10.5.1 | |
IBM Operational Decision Manager | =8.11 | |
IBM Operational Decision Manager | =8.11.0.1 | |
IBM Operational Decision Manager | =8.12.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22319 is characterized as a high severity vulnerability due to its potential for remote code execution.
To remediate CVE-2024-22319, update IBM Operational Decision Manager to a patched version as specified in the vendor's guidance.
CVE-2024-22319 impacts IBM Operational Decision Manager versions 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1.
CVE-2024-22319 allows for remote code execution attacks via JNDI injection when unchecked arguments are passed to a specific API.
Using IBM Operational Decision Manager with CVE-2024-22319 without applying the necessary patches poses a significant security risk.