CVE-2010-4417
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 79%
from disclosure to weapon1779 days
Published on NVDJan 19
1st PoC+1779d
metasploitJun 9
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38859cve_referencewww.exploit-db.com/exploits/38859/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/42978https://exchange.xforce.ibmcloud.com/vulnerabilities/64772https://www.exploit-db.com/exploits/38859/http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlhttp://www.securityfocus.com/bid/45854http://www.securitytracker.com/id?1024981http://www.vupen.com/english/advisories/2011/0143http://www.zerodayinitiative.com/advisories/ZDI-11-020/