CVE-2009-3548

Apache Tomcat - Credentials Management

Title source: rule

Description

The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/31433
exploitdb WORKING POC
rubyremotemultiple
https://www.exploit-db.com/exploits/16317

References (26)

... and 6 more

Scores

EPSS 0.8688
EPSS Percentile 99.4%

Classification

CWE
CWE-255
Status draft

Affected Products (50)

apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more

Timeline

Published Nov 12, 2009
Tracked Since Feb 18, 2026