Sploitus

Exploit for IBM Cognos Express Server Backdoor Account Remote Code Execution

saint · 2010-05-25

Exploit Code

MARKDOWN31 lines
## https://sploitus.com/exploit?id=SAINT:B0A1D9F854F22F1DE9F592C0BF728365
Added: 05/25/2010  
CVE: [CVE-2010-0557](<https://vulners.com/cve/CVE-2010-0557>)  
BID: [38084](<http://www.securityfocus.com/bid/38084>)  
OSVDB: [62118](<http://www.osvdb.org/62118>)  


### Background

[IBM Cognos Express](<http://www-01.ibm.com/software/data/cognos/products/cognos-express/>) is an integrated business intelligence (BI) and planning solution which delivers the essential reporting, analysis, dashboard, scorecard, planning, budgeting and forecasting capabilities that midsize companies need. 

### Problem

The vulnerability is due to hard-coded user credentials, with manager-level permissions, installed by default in the user configuration of the bundled Tomcat Manager server. Remote unauthenticated attackers can exploit this vulnerability by using these credentials to connect to the vulnerable server on port 19300/TCP and deploy a malicious web application on a vulnerable system. Injected code will run with the privileges of the Tomcat server process. On Windows systems, the Tomcat server runs as SYSTEM. 

### Resolution

Follow the directions in the IBM Advisory [SWG21419179](<http://www-01.ibm.com/support/docview.wss?uid=swg21419179>). 

### References

<http://secunia.com/advisories/38457/>  


### Limitations

Exploit works on IBM Cognos Express 9.0. 

### Platforms

Windows