← Vulnerability feed

Vulnerability record · CVE-2010-4417 · published 19 January 2011

CVE-2010-4417: Oracle Fusion Middleware Beehive Services null-byte file write and JSP execution

Oracle · Beehive

Oracle Fusion Middleware's Services for Beehive component contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availability. A third-party report claims the evaluation parameter in voice-servlet/prompt-qa/Index.jspf mishandles null (%00) bytes used in a filename, allowing creation of a file with an executable extension and execution of arbitrary JSP code. Oracle has not commented on that claim, and the official description remains vague.

7.5 CVSS 2.0 High EPSS 76% · top 0.5%
7.5CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution potential with a public exploit and very high EPSS, though Oracle has not confirmed the technical details and no KEV listing exists.

What it is

Oracle Fusion Middleware's Services for Beehive component contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availability. A third-party report claims the evaluation parameter in voice-servlet/prompt-qa/Index.jspf mishandles null (%00) bytes used in a filename, allowing creation of a file with an executable extension and execution of arbitrary JSP code. Oracle has not commented on that claim, and the official description remains vague.

Impact

An unauthenticated remote attacker can potentially write a file with an executable extension and run arbitrary JSP code, gaining code execution in the application server context and compromising confidentiality, integrity, and availability.

Attack surface

Reachable over the network via HTTP against the Beehive Services voice-servlet/prompt-qa/Index.jspf endpoint; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.763, 99.5th percentile) and a public Exploit-DB entry (38859) exists, indicating exploit code is available. No ransomware association is documented.

What to do

  • Apply the Oracle January 2011 Critical Patch Update or a later supported Fusion Middleware release that addresses the Beehive Services issue.
  • If Beehive Services voice-servlet/prompt-qa is not required, disable or remove the component and block access to Index.jspf at the web tier.
  • Reject or sanitize null bytes and path traversal sequences in the evaluation parameter and any filename-derived input.
  • Restrict the application server's file-write permissions so uploaded or generated files cannot be placed in executable web directories.
  • Monitor Oracle advisories for updated guidance, since Oracle has not confirmed the third-party technical details.

Detection

  • Inspect web server and application logs for requests to voice-servlet/prompt-qa/Index.jspf containing %00 or null-byte sequences in parameters.
  • Alert on creation of new files with .jsp or other executable extensions in web-accessible directories.
  • Monitor for unexpected JSP execution or outbound connections originating from the Fusion Middleware application server process.
  • Correlate Exploit-DB 38859 signatures and known Beehive Services exploit patterns against inbound HTTP traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-4417 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2010-4417), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.