VMware VirtualCenter Update 6b and ESX 3.5 patch update JRE.
VirtualCenter 2.5 previous to Update 6b
ESX 3.5 without patch ESX350-201203401-SG
a. VirtualCenter and ESX, Oracle (Sun) JRE update 1.5.0_32
Oracle (Sun) JRE is updated to version 1.5.0_32, which addresses multiple security issues that existed in earlier releases of Oracle(Sun) JRE.
Oracle has documented the CVE identifiers that are addressed in JRE 1.5.0_32 in the Oracle Java SE Critical Patch Update Advisory of October 2011.
Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available.
* hosted products are VMware Workstation, Player, ACE, Fusion.
** this product uses the Oracle (Sun) JRE 1.6.0 family
VMware Virtual Center 2.5 Update 6b
vCenter Server DVD image - English only versionFile type: iso
vCenter Server as a Zip file - English only version
File type: zip
VMware vCenter Converter BootCD for vCenter Server
File type: .zip
VMware vCenter Converter CLI for Linux platform
File type: .tar.gz
2012-03-08 VMSA-2012-0003 Initial security advisory in conjunction with the release of VirtualCenter Update 6b and patches for ESX 3.5 and ESXi 3.5 on 2012-03-08.
2012-09-13 VMSA-2012-0003.1 Updated security advisory in conjunction with the release of vSphere 4.0 U4a on 2012-09-12 and ESX 4.0 patches on 2012-09-13.
E-mail list for product security notifications and announcements:
This Security Advisory is posted to the following lists: