First published: Thu Oct 14 2010(Updated: )
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of unspecified functions using XML-RPC.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle VM | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3585 has a moderate severity rating due to its potential impact on confidentiality, integrity, and availability.
To fix CVE-2010-3585, upgrade to a later version of Oracle VM that addresses this vulnerability.
CVE-2010-3585 can be exploited by remote authenticated users with access to the affected Oracle VM 2.2.1.
CVE-2010-3585 specifically affects the OracleVM component related to the ovs-agent.
The potential impacts of CVE-2010-3585 include risks to confidentiality, integrity, and availability of the system.