PT-2024-3781 · Ibm · Ibm Operational Decision Manager

Sonny

·

Published

2024-01-29

·

Updated

2024-09-04

·

CVE-2024-22319

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Operational Decision Manager versions 8.10.3 through 8.12.0.1
Description The issue is related to a remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. This could allow a remote attacker to conduct an LDAP injection by sending a request with a specially crafted argument.
Recommendations For IBM Operational Decision Manager versions 8.10.3 through 8.12.0.1, consider disabling the API that accepts unchecked arguments until a patch is available. Restrict access to the vulnerable API to minimize the risk of exploitation. Avoid using unchecked arguments in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2024-04134
CVE-2024-22319

Affected Products

Ibm Operational Decision Manager