{"api_version":"1","generated_at":"2026-07-23T11:41:38+00:00","cve":"CVE-2010-4417","urls":{"html":"https://cve.report/CVE-2010-4417","api":"https://cve.report/api/cve/CVE-2010-4417.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-4417","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-4417"},"summary":{"title":"CVE-2010-4417","description":"Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the January 2011 CPU.  Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.","state":"PUBLISHED","assigner":"oracle","published_at":"2011-01-19 16:00:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64772","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64772","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-020/","name":"http://www.zerodayinitiative.com/advisories/ZDI-11-020/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/38859/","name":"https://www.exploit-db.com/exploits/38859/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle BeeHive 2 - 'voice-servlet processEvaluation()' Write File (Metasploit) - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1024981","name":"http://www.securitytracker.com/id?1024981","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker: Oracle Fusion Middleware Flaws Let Remote Users Execute Arbitrary Code, Access and Modify Data, and Deny Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0143","name":"http://www.vupen.com/english/advisories/2011/0143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/45854","name":"http://www.securityfocus.com/bid/45854","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Fusion Middleware CVE-2010-4417 Beehive Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle Critical Patch Update Pre-Release Announcement - January   2011","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/42978","name":"http://secunia.com/advisories/42978","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle Beehive JSP Code Execution Vulnerability - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-4417","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4417","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"4417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"beehive","cpe6":"2.0.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"beehive","cpe6":"2.0.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"beehive","cpe6":"2.0.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"beehive","cpe6":"2.0.1.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"beehive","cpe6":"2.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:43:14.683Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2011-0143","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0143"},{"name":"38859","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/38859/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-020/"},{"name":"oracle-beehive-index-code-execution(64772)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64772"},{"name":"1024981","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024981"},{"name":"42978","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42978"},{"name":"45854","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/45854"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-01-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the January 2011 CPU.  Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"ADV-2011-0143","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0143"},{"name":"38859","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/38859/"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-11-020/"},{"name":"oracle-beehive-index-code-execution(64772)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64772"},{"name":"1024981","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024981"},{"name":"42978","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42978"},{"name":"45854","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/45854"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2010-4417","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the January 2011 CPU.  Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2011-0143","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0143"},{"name":"38859","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/38859/"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-11-020/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-11-020/"},{"name":"oracle-beehive-index-code-execution(64772)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64772"},{"name":"1024981","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024981"},{"name":"42978","refsource":"SECUNIA","url":"http://secunia.com/advisories/42978"},{"name":"45854","refsource":"BID","url":"http://www.securityfocus.com/bid/45854"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2010-4417","datePublished":"2011-01-19T15:00:00.000Z","dateReserved":"2010-12-06T00:00:00.000Z","dateUpdated":"2024-08-07T03:43:14.683Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-01-19 16:00:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:beehive:2.0.1.0:*:*:*:*:*:*:*","matchCriteriaId":"DCE61AF6-39E4-4DF9-B1F3-4910F9EA144D"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:beehive:2.0.1.1:*:*:*:*:*:*:*","matchCriteriaId":"599BE48F-B69E-475F-9D6D-C648E8F812AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:beehive:2.0.1.2:*:*:*:*:*:*:*","matchCriteriaId":"248EE1FD-0D85-4306-B1A5-F8BA0352478D"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:beehive:2.0.1.2.1:*:*:*:*:*:*:*","matchCriteriaId":"FE6DB81B-828B-4CC5-8CE6-AA68669C85B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:beehive:2.0.1.3:*:*:*:*:*:*:*","matchCriteriaId":"7CB17F35-F88C-4287-A999-A6B6822762F7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"4417","Ordinal":"1","Title":"CVE-2010-4417","CVE":"CVE-2010-4417","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"4417","Ordinal":"1","NoteData":"Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the January 2011 CPU.  Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.","Type":"Description","Title":"CVE-2010-4417"},{"CveYear":"2010","CveId":"4417","Ordinal":"2","NoteData":"2011-01-19","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"4417","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}