QID 150821
Date Published: 2024-03-06
QID 150821: IBM Operational Decision Manager - JNDI Injection Vulnerability (CVE-2024-22320)
IBM Operational Decision Manager is a comprehensive decision automation platform that allows organizations to model, deploy, and manage business rules and decisions.
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM.
Affected Versions:
IBM Operational Decision Manager version 8.10.3
IBM Operational Decision Manager version 8.10.4
IBM Operational Decision Manager version 8.10.5.1
IBM Operational Decision Manager version 8.11.0.1
IBM Operational Decision Manager version 8.11.1
IBM Operational Decision Manager version 8.12.0.1
QID Detection Logic (Unauthenticated):
The QID sends a HTTP GET request with specially crafted payload to the 'decisioncenter-api/v1/about' endpoint, where vulnerable servers will make a DNS query that will trigger Qualys Periscope detection mechanism.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the target system.
- 7112382 -
www.ibm.com/support/pages/node/7112382
CVEs related to QID 150821
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM Security Advisory |
|