CVE-2010-4094
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.
- Affected products
- Ibm Rational Quality Manager, Rational Test Lab Manager, Apache Tomcat
- Ibm Rational Quality Manager
- All versions
- Ibm Rational Test Lab Manager
- All versions
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 64.5% (99th percentile)
- Weakness
- CWE-255
- NVD status
- Modified
- Published
- 2010-10-26
CVE-2010-4094 at NVD
10 known exploits for CVE-2010-4094
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Tomcat Manager Code Execution Exploit
Apache Tomcat Manager Code Execution
Apache Tomcat Manager Authenticated Upload Code Execution
Tomcat Application Manager Login Utility
Apache Tomcat Manager Application Deployer Authenticated Code Execution
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
IBM Rational Quality Manager and Test Lab Manager Policy Bypass
IBM Rational Quality Manager and Test Lab Manager Policy Bypass
IBM Rational Quality Manager and Test Lab Manager Policy Bypass
IBM Rational Quality Manager and Test Lab Manager Policy Bypass