## https://sploitus.com/exploit?id=SAINT:9E88983E6D2E3F9BD58C6DCB531A7E97
Added: 11/05/2010
CVE: [CVE-2009-3548](<https://vulners.com/cve/CVE-2009-3548>)
BID: [36954](<http://www.securityfocus.com/bid/36954>)
OSVDB: [60176](<http://www.osvdb.org/60176>)
### Background
HP Performance Manager Software is a web-based analysis and visualization tool that analyzes performance trends of applications, systems, and services. HP Performance Manager incorporates Apache Tomcat 5 to help serve custom web applications.
### Problem
An unauthorized file upload vulnerability exists in HP Performance Manager. HP Performance Manager generates credentials for a default user/password combination in Apache Tomcat. A remote attacker can leverage this vulnerability by sending a crafted HTTP request using the default credentials. Once authenticated, the attacker can upload a malicious web application to a vulnerable system.
### Resolution
Apply the fix referenced in [HP Security Bulletin HPSBMA02535](<http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02181353>).
### References
<http://secunia.com/advisories/39847/>
### Limitations
Exploit works on HP Performance Manager 8.1 on Microsoft Windows Server 2003 and Windows Server 2008.
It may take longer than usual to establish the connection after successful exploitation because it takes time for the affected server to deploy the malicious WAR file.
### Platforms
Windows