CVE-2024-22320
9.8
CRITICAL · CVSS 3.1 · EPSS 73.4% (pctl 99)
Patch early
EPSS 73.4% — above the 10% action threshold.
Description
IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 73.4% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2024-02-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | operational decision manager |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/279146
- https://www.ibm.com/support/pages/node/7112382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/279146
- https://www.ibm.com/support/pages/node/7112382
- https://www.vicarius.io/vsociety/posts/unveiling-cve-2024-22320-a-novices-journey-to-exploiting-java-deserialization-rce-in-ibm-odm
→ the Explorer · watch your stack · NVD