CVE-2010-4094
IBM Rational Quality Manager - Credentials Management
Title source: ruleDescription
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16317
metasploit
WORKING POC
EXCELLENT
rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/tomcat_mgr_upload.rb
metasploit
WORKING POC
EXCELLENT
by jduck · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/tomcat_mgr_deploy.rb
References (7)
Scores
EPSS
0.8416
EPSS Percentile
99.3%
Details
CWE
CWE-255
Status
published
Products (2)
ibm/rational_quality_manager
ibm/rational_test_lab_manager
Published
Oct 26, 2010
Tracked Since
Feb 18, 2026