IBM Operational Decision Manager code execution
87Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 73%
from disclosure to weapon
Published on NVDFeb 2
VulnCheck+49d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesVulnCheck
In short
IBM Operational Decision Manager has a flaw that allows authenticated users to run malicious code on the server by sending specially crafted requests. This happens because the software unsafely processes serialized data, making it a critical security risk.
Technical detail
CVE-2024-22320 is an unsafe deserialization vulnerability (CWE-502) in IBM ODM 8.10.3 that permits authenticated remote attackers to achieve arbitrary code execution with SYSTEM privileges. The attack vector involves sending malicious serialized objects that are deserialized without proper validation, leading to instantiation of attacker-controlled code.
Summary generated and translated by AI from the official description.
IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
IBM · Operational Decision Manager