VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users." Patch information with appropriate login and password:
http://www.vmware.com/security/advisories/VMSA-2008-0012.html
4. Solution
Please review the patch/release notes for your product and version
and verify the md5sum of your downloaded file.
VirtualCenter
-------------
VMware VirtualCenter 2.5 Update 2 build 104263
www.vmware.com/download/download.do
DVD iso image
md5sum: 83de404fa073bc1fde9acd080f21e688
Zip file
md5sum: 3297f1e47c6b018ac8190f11bd022d5b
Release Notes
www.vmware.com/support/vi3/doc/vi3_esx35u2_vc25u2_rel_notes.html
VMware VirtualCenter 2.0.2 Update 5 build 104182
www.vmware.com/downloads/download.do
DVD iso image
md5sum: 5fee5d2d97b482e0d0cb47da7d8e7c34
Zip file
md5sum: cd468aab309745c12ee5516652aafbcb
Release Notes
www.vmware.com/support/vi3/doc/releasenotes_vc202u5.html
Publication date: Wed, 13 Aug 2008 17:42:00 +0000