The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 6.0.24Upgrade Apache Tomcat to 5.5.29 | May 17, 2012 | Nov 12, 2009 |
| Hpux | — | — | Aug 11, 2017 | Nov 12, 2009 |
| Vmsa 2011 0003 | — | Upgrade VMware ESX 4.0 to build number 360236Upgrade VMware ESX 4.1 to build number 348481 | Feb 16, 2011 | Nov 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub