Vulnerability record · CVE-2024-22319 · published 2 February 2024
CVE-2024-22319: IBM Operational Decision Manager JNDI injection remote code execution
Ibm · Operational Decision Manager
IBM Operational Decision Manager versions 8.10.3 through 8.12.0.1 pass an unchecked argument to a certain API, allowing JNDI injection. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the server.
Description
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with very high EPSS, makes this a top remediation priority.
What it is
IBM Operational Decision Manager versions 8.10.3 through 8.12.0.1 pass an unchecked argument to a certain API, allowing JNDI injection. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the server.
Impact
Successful exploitation gives the attacker remote code execution with high impact to confidentiality, integrity and availability. The attacker can run arbitrary code under the privileges of the affected service.
Attack surface
The flaw is network reachable (AV:N) with no authentication (PR:N) and no user interaction (UI:N) required, per the CVSS vector. It is triggered by supplying a crafted argument to the affected API.
Exploitation
The record does not list this CVE in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.764 (99.5th percentile), indicating elevated likelihood of exploitation. No public exploit reference is included in the supplied data.
What to do
- Apply the IBM patch referenced in IBM support page node/7112382 for the affected Operational Decision Manager versions.
- If immediate patching is not possible, restrict network access to the affected API and service ports to trusted hosts only.
- Disable or restrict JNDI lookups and remote class loading in the JVM where feasible.
- Monitor and block outbound connections from the ODM server to untrusted hosts to limit JNDI callback abuse.
- Review and harden the API input validation path that passes the unchecked argument.
Detection
- Monitor application and server logs for JNDI lookup strings, LDAP/RMI/DNS callback patterns, or unusual class loading in ODM processes.
- Alert on outbound network connections from ODM servers to unexpected external or internal hosts on LDAP, RMI or DNS ports.
- Detect anomalous child processes or command execution spawned by the ODM service account.
- Track requests to the affected API for malformed or unexpected arguments that could indicate injection attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/279145 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/7112382 | PatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/279145 | VDB EntryVendor Advisory |
| https://www.ibm.com/support/pages/node/7112382 | PatchVendor Advisory |
Track CVE-2024-22319 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-22319), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.