← Vulnerability feed

Vulnerability record · CVE-2010-3585 · published 14 October 2010

CVE-2010-3585: Oracle VM ovs-agent unspecified vulnerability allows authenticated compromise

Oracle · Vm

Oracle VM 2.2.1 contains an unspecified vulnerability in the OracleVM component related to ovs-agent. A remote authenticated user can fully affect confidentiality, integrity, and availability. A third-party researcher claims the issue involves exposure of unspecified functions via XML-RPC, but Oracle has not confirmed this.

9.0 CVSS 2.0 High EPSS 52% · top 1.1%
9.0CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of unspecified functions using XML-RPC.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 2.0 score of 9.0 with complete impact and a very high EPSS percentile, though exploitation requires valid credentials and no KEV listing.

What it is

Oracle VM 2.2.1 contains an unspecified vulnerability in the OracleVM component related to ovs-agent. A remote authenticated user can fully affect confidentiality, integrity, and availability. A third-party researcher claims the issue involves exposure of unspecified functions via XML-RPC, but Oracle has not confirmed this.

Impact

An attacker with valid credentials gains full compromise of confidentiality, integrity, and availability on the affected Oracle VM host. This could allow control over virtual machine management functions or the host itself.

Attack surface

Reachable over the network (AV:N) with low attack complexity (AC:L), but requires authentication (Au:S). No user interaction is indicated. The specific interface is unknown, though the third-party claim points to XML-RPC functions.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged; EPSS is high at 0.52052 (98.9th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Apply the Oracle October 2010 Critical Patch Update for Oracle VM 2.2.1 or upgrade to a supported Oracle VM release.
  • Restrict network access to ovs-agent and XML-RPC management interfaces to trusted administrative networks only.
  • Enforce least privilege and strong authentication for Oracle VM management accounts; remove or disable unused accounts.
  • Monitor for and block unauthorized XML-RPC calls to Oracle VM management endpoints.
  • If patching is not immediately possible, isolate affected Oracle VM hosts from untrusted networks.

Detection

  • Monitor ovs-agent and XML-RPC service logs for unexpected or malformed requests from authenticated users.
  • Alert on anomalous management actions from Oracle VM accounts, such as unusual VM configuration changes or privilege use.
  • Baseline normal ovs-agent network traffic and flag deviations, especially from non-administrative hosts.
  • Audit authentication logs for successful logins followed by suspicious management operations on Oracle VM hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-3585 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2010-3585), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.