CVE-2009-3548
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
- Affected products
- Apache Tomcat, Hp-Ux
- Apache Tomcat
- = 3.0, 3.1, 3.1.1, 3.2, 3.2.1, 3.2.2, 3.2.3, 3.2.4, 3.3, 3.3.1, 3.3.1a, 3.3.2, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.4, 4.1.5, 4.1.6, 4.1.7, 4.1.8, 4.1.9, 4.1.10, 4.1.11, 4.1.12, 4.1.13, 4.1.14, 4.1.15, 4.1.16, 4.1.17, 4.1.18, 4.1.19, 4.1.20
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 79.0% (100th percentile)
- Weakness
- CWE-255
- NVD status
- Modified
- Published
- 2009-11-12
CVE-2009-3548 at NVD
12 known exploits for CVE-2009-3548
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
Apache Tomcat Manager Code Execution Exploit
Apache Tomcat Manager Code Execution
Apache Tomcat Manager Authenticated Upload Code Execution
Tomcat Application Manager Login Utility
Apache Tomcat Manager Application Deployer Authenticated Code Execution
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Performance Manager Apache Tomcat Policy Bypass
HP Performance Manager Apache Tomcat Policy Bypass
HP Performance Manager Apache Tomcat Policy Bypass
HP Performance Manager Apache Tomcat Policy Bypass
Apache Tomcat Windows安装程序默认空口令漏洞