Unveiling CVE-2024-22319: A Novice's Journey of a whitebox pentest - from nothing to everything - JNDI Injection RCE in IBM ODM

Unveiling CVE-2024-22319: A Novice's Journey of a whitebox pentest - from nothing to everything - JNDI Injection RCE in IBM ODM

CVEs

9.8 Critical Severity

Apps

8.10.5.1.*
8.12.0.1.*
8.9.0.2.*
8.9.1.0.*
8.10.2.0.*
8.7.1.2.*
8.8.1.1.*
8.8.1.2.*
8.8.0.1.*
8.8.1.0.*

Screenshots from the blog posts

images/clt2v017yacmg1hn0cx2214x3.pngimages/clt2v017yacmg1hn0cx2214x3.png

Summary

Certain versions of IBM Operational Decision Manager allow a remote unauthenticated attacker to execute arbitrary code on the system, caused by JNDI injection in an unprotected REST API. This post acts a complete hands-on guide to understand and exploit this JNDI injection vulnerability without any prior experience with such vulnerabilities. The complete process is performed considering a whitebox pentest, right from the very start is shown to make is easy to follow for even the beginner audience!

Description

Total vcoins

53.1K

Social media links

Comments (0)