← Vulnerability feed

Vulnerability record · CVE-2024-22319 · published 2 February 2024

CVE-2024-22319: IBM Operational Decision Manager JNDI injection remote code execution

Ibm · Operational Decision Manager

IBM Operational Decision Manager versions 8.10.3 through 8.12.0.1 pass an unchecked argument to a certain API, allowing JNDI injection. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the server.

9.8 CVSS 3.1 Critical EPSS 76% · top 0.5% CWE-74 · Injection
9.8CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with very high EPSS, makes this a top remediation priority.

What it is

IBM Operational Decision Manager versions 8.10.3 through 8.12.0.1 pass an unchecked argument to a certain API, allowing JNDI injection. A remote, unauthenticated attacker can exploit this to execute arbitrary code on the server.

Impact

Successful exploitation gives the attacker remote code execution with high impact to confidentiality, integrity and availability. The attacker can run arbitrary code under the privileges of the affected service.

Attack surface

The flaw is network reachable (AV:N) with no authentication (PR:N) and no user interaction (UI:N) required, per the CVSS vector. It is triggered by supplying a crafted argument to the affected API.

Exploitation

The record does not list this CVE in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.764 (99.5th percentile), indicating elevated likelihood of exploitation. No public exploit reference is included in the supplied data.

What to do

  • Apply the IBM patch referenced in IBM support page node/7112382 for the affected Operational Decision Manager versions.
  • If immediate patching is not possible, restrict network access to the affected API and service ports to trusted hosts only.
  • Disable or restrict JNDI lookups and remote class loading in the JVM where feasible.
  • Monitor and block outbound connections from the ODM server to untrusted hosts to limit JNDI callback abuse.
  • Review and harden the API input validation path that passes the unchecked argument.

Detection

  • Monitor application and server logs for JNDI lookup strings, LDAP/RMI/DNS callback patterns, or unusual class loading in ODM processes.
  • Alert on outbound network connections from ODM servers to unexpected external or internal hosts on LDAP, RMI or DNS ports.
  • Detect anomalous child processes or command execution spawned by the ODM service account.
  • Track requests to the affected API for malformed or unexpected arguments that could indicate injection attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-22319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2018-1821Ibm operational decision manager xml external entity (xxe) vulnerabilityIBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…EPSS 16%8.8CVE-2024-22320IBM Operational Decision Manager unsafe deserialization RCEIBM Operational Decision Manager 8.10.3 deserializes untrusted data, allowing a remote authenticated attacker to execute arbitrary code by sending a …EPSS 73%analysed7.4CVE-2025-2824Ibm operational decision manager open redirect vulnerabilityIBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using an…EPSS 0.32%6.1CVE-2025-1551Ibm operational decision manager cross-site scripting vulnerabilityIBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauth…EPSS 0.26%6.0CVE-2014-0944Ibm operational decision manager cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, …EPSS 0.73%5.0CVE-2014-6114Ibm operational decision manager information exposure vulnerabilityThe Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Deci…EPSS 2.2%4.3CVE-2014-0946Ibm operational decision manager information exposure vulnerabilityThe RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does no…EPSS 1.8%3.5CVE-2014-0945Ibm operational decision manager cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 bef…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-22319), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.