First published: Thu Oct 14 2010(Updated: )
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of multiple unspecified functions through XML-RPC that allow execution of arbitrary OS commands.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle VM | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3583 is considered a critical vulnerability due to its potential impact on confidentiality, integrity, and availability.
To fix CVE-2010-3583, you should upgrade to a newer, patched version of Oracle VM that addresses this vulnerability.
CVE-2010-3583 affects remote authenticated users of Oracle VM 2.2.1.
Exploiting CVE-2010-3583 can compromise the confidentiality, integrity, and availability of system resources.
There are no specific workarounds for CVE-2010-3583 recommended; updating to a secure version is the most effective solution.