Vulnerability record · CVE-2010-3600 · published 19 January 2011
CVE-2010-3600: Oracle Client System Analyzer remote code execution via exposed JSP upload
Oracle · Database Server
An unspecified vulnerability in the Client System Analyzer component of Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity and availability. Oracle has not confirmed third-party claims that an exposed JSP script accepting XML uploads, combined with NULL bytes in an unspecified parameter, permits arbitrary code execution.
Description
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue involves an exposed JSP script that accepts XML uploads in conjunction with NULL bytes in an unspecified parameter that allow execution of arbitrary code.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution potential with a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.
What it is
An unspecified vulnerability in the Client System Analyzer component of Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity and availability. Oracle has not confirmed third-party claims that an exposed JSP script accepting XML uploads, combined with NULL bytes in an unspecified parameter, permits arbitrary code execution.
Impact
An unauthenticated remote attacker can potentially execute arbitrary code on the affected server, gaining full control over confidentiality, integrity and availability of the Oracle Database and Enterprise Manager components.
Attack surface
Reachable over the network via the Client System Analyzer component with no authentication required (CVSS vector AV:N/AC:L/Au:N). No user interaction is indicated by the vector or description.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.767 (99.5th percentile), indicating a strong likelihood of exploitation activity; reference tags are vendor advisories only, with no public exploit tag.
What to do
- Apply the January 2011 Oracle Critical Patch Update for Database Server and Enterprise Manager Grid Control.
- If patching is not immediately possible, restrict network access to the Client System Analyzer component and its JSP endpoints to trusted hosts only.
- Disable or remove the Client System Analyzer component if it is not required in the environment.
- Monitor and filter HTTP requests containing NULL bytes or unexpected XML uploads to the affected JSP script.
- Verify that the affected Oracle versions (11.1.0.7, 11.2.0.1, 10.2.0.5) are upgraded to a supported release.
Detection
- Inspect web server and Oracle HTTP logs for POST requests to Client System Analyzer JSP endpoints with XML payloads or NULL byte sequences.
- Monitor for unexpected child processes spawned by the Oracle web listener or JVM, which may indicate code execution.
- Alert on outbound network connections from the Oracle Database or Enterprise Manager host to unknown external addresses.
- Review file system changes in Oracle web application directories for dropped JSP or executable files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-3600 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-3600), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.