Update for VirtualCenter updates the Tomcat package to version 5.5.27 which addresses multiple security issues that existed in the previous version of Apache Tomcat. The relevant releases are VirtualCenter 2.5 before Update 4.
This vulnerability can be exploited remotely only if the attacker has access to the Service Console network. Security best practices provided by VMware recommend that the Service Console be isolated from the VM network. Please see
http://www.vmware.com/resources/techresources/726 for more information on VMware security best practices.
The currently installed version of Tomcat depends on your patch deployment history. Please review the patch/release notes for your product and version and verify the md5sum of your downloaded file.
VMware VirtualCenter 2.5 Update 4
http://www.vmware.com/download/download.do?downloadGroup=VC250U4
DVD iso image - md5sum: 4304334ed7662b6a43646e6dde0956d2
Zip file - md5sum: 1306cb9b25e28a06bab84257d7cbf38f
Release Notes
http://www.vmware.com/support/vi3/doc/vi3_vc25u4_rel_notes.html