# CVE-2024-22319

## Summary

- **CVE ID:** CVE-2024-22319
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-74
- **Published:** Feb 2, 2024
- **Last Modified:** Mar 13, 2026

## Description

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

## Affected Products

- IBM — Operational Decision Manager (8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1, 8.12.0.1)

## References

- [CNA](https://www.ibm.com/support/pages/node/7112382)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/279145)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 76.40%
- **EPSS Percentile:** 99.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._