← Vulnerability feed

Vulnerability record · CVE-2010-3600 · published 19 January 2011

CVE-2010-3600: Oracle Client System Analyzer remote code execution via exposed JSP upload

Oracle · Database Server

An unspecified vulnerability in the Client System Analyzer component of Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity and availability. Oracle has not confirmed third-party claims that an exposed JSP script accepting XML uploads, combined with NULL bytes in an unspecified parameter, permits arbitrary code execution.

7.5 CVSS 2.0 High EPSS 77% · top 0.5%
7.5CVSS 2.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue involves an exposed JSP script that accepts XML uploads in conjunction with NULL bytes in an unspecified parameter that allow execution of arbitrary code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution potential with a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.

What it is

An unspecified vulnerability in the Client System Analyzer component of Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity and availability. Oracle has not confirmed third-party claims that an exposed JSP script accepting XML uploads, combined with NULL bytes in an unspecified parameter, permits arbitrary code execution.

Impact

An unauthenticated remote attacker can potentially execute arbitrary code on the affected server, gaining full control over confidentiality, integrity and availability of the Oracle Database and Enterprise Manager components.

Attack surface

Reachable over the network via the Client System Analyzer component with no authentication required (CVSS vector AV:N/AC:L/Au:N). No user interaction is indicated by the vector or description.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.767 (99.5th percentile), indicating a strong likelihood of exploitation activity; reference tags are vendor advisories only, with no public exploit tag.

What to do

  • Apply the January 2011 Oracle Critical Patch Update for Database Server and Enterprise Manager Grid Control.
  • If patching is not immediately possible, restrict network access to the Client System Analyzer component and its JSP endpoints to trusted hosts only.
  • Disable or remove the Client System Analyzer component if it is not required in the environment.
  • Monitor and filter HTTP requests containing NULL bytes or unexpected XML uploads to the affected JSP script.
  • Verify that the affected Oracle versions (11.1.0.7, 11.2.0.1, 10.2.0.5) are upgraded to a supported release.

Detection

  • Inspect web server and Oracle HTTP logs for POST requests to Client System Analyzer JSP endpoints with XML payloads or NULL byte sequences.
  • Monitor for unexpected child processes spawned by the Oracle web listener or JVM, which may indicate code execution.
  • Alert on outbound network connections from the Oracle Database or Enterprise Manager host to unknown external addresses.
  • Review file system changes in Oracle web application directories for dropped JSP or executable files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-3600 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1953Apache commons configuration vulnerabilityApache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…EPSS 6.8%10.0CVE-2015-4863Oracle database server vulnerabilityUnspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to…EPSS 3.1%10.0CVE-2013-1534Oracle database server vulnerabilityUnspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows …EPSS 3.7%10.0CVE-2010-0071Oracle database server vulnerabilityUnspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers t…EPSS 9.8%10.0CVE-2009-1979Oracle Database Network Authentication component remote code execution riskAn unspecified flaw in the Network Authentication component of Oracle Database 10.1.0.5 and 10.2.0.4 lets remote attackers affect confidentiality, in…EPSS 76%analysed10.0CVE-2009-1985Oracle database server vulnerabilityUnspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attacke…EPSS 5.4%10.0CVE-2009-1992Oracle database server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidenti…EPSS 4.2%10.0CVE-2008-1818Oracle database server vulnerabilityUnspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2010-3600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.