QID 731201
Date Published: 2024-02-23
QID 731201: IBM Operational Decision Manager Multiple Vulnerabilities
IBM Operational Decision Manager (ODM) is a decision management platform that streamlines decision authoring and editing, with enterprise-grade features such as a traceability, simulation, versioning and auditing. IBM ODM helps organizations build precise decisions that help organizations increase efficiency, manage compliance, and improve operational agility.
CVE-2024-22319: IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API.
CVE-2024-22320: IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM.
Affected Versions:
IBM Operational Decision Manager version 8.10.3
IBM Operational Decision Manager version 8.10.4
IBM Operational Decision Manager version 8.10.5.1
IBM Operational Decision Manager version 8.11.0.1
IBM Operational Decision Manager version 8.11.1
IBM Operational Decision Manager version 8.12.0.1
QID Detection Logic (Unauthenticated):
This QID sends a JNDI payload to the 'decisioncenter-api/v1/about' endpoint and checks for a callback on the scanner. Please note that this QID relies on a callback to the scanner on a random port. The target must be enabled to connect back to any random port on the scanner.
Successful exploitation of the vulnerabilities may allow an unauthenticated remote attacker to execute arbitrary commands as SYSTEM, leading to complete system compromise.
- IBM Security Advisory -
www.ibm.com/support/pages/node/7112382
CVEs related to QID 731201
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM Security Advisory |
|