CVE-2009-3548
Apache Tomcat - Credentials Management
Title source: ruleDescription
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/31433
References (26)
... and 6 more
Scores
EPSS
0.8688
EPSS Percentile
99.4%
Classification
CWE
CWE-255
Status
draft
Affected Products (50)
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
apache/tomcat
... and 35 more
Timeline
Published
Nov 12, 2009
Tracked Since
Feb 18, 2026