I don't know how things are today, but in 2009 it was possible. See, for instance, the paper Hey, You, Get Off of My Cloud:
Exploring Information Leakage in
Third-Party Compute Clouds at
http://cseweb.ucsd.edu/~hovav/dist/cloudsec.pdf
From the abstract:
Using the Amazon EC2 service as a case study, we show that
it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then
instantiate new VMs until one is placed co-resident with the
target. We explore how such placement can then be used to
mount cross-VM side-channel attacks to extract information
from a target VM on the same machine.
Scared yet?
From the abstract: Using the Amazon EC2 service as a case study, we show that it is possible to map the internal cloud infrastructure, identify where a particular target VM is likely to reside, and then instantiate new VMs until one is placed co-resident with the target. We explore how such placement can then be used to mount cross-VM side-channel attacks to extract information from a target VM on the same machine. Scared yet?