peter bassill · operator
$ cve CVE-2024-22320 JSON

CVE-2024-22320

9.8
CRITICAL · CVSS 3.1 · EPSS 73.4% (pctl 99)

Patch early

EPSS 73.4% — above the 10% action threshold.

Description

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS73.4% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2024-02-02
Last modified2026-06-17

Affected (1)

VendorProduct
ibmoperational decision manager

References

→ the Explorer  ·  watch your stack  ·  NVD