CVE-2009-3548 is an insecure-default-credentials vulnerability in the Windows installer for Apache Tomcat. Installations of Tomcat 6.0.0 through 6.0.20 and 5.5.0 through 5.5.28 can create the administrative Manager user with a blank password unless the installer user changes it. Earlier releases may also be affected. An unauthenticated remote party can authenticate using the blank password and obtain administrative privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'tomcat_mgr_upload.rb', which targets Apache Tomcat servers with the Manager application enabled. The exploit requires valid credentials for the Tomcat Manager and leverages the /manager/html/upload endpoint to upload a malicious WAR file containing a JSP payload. Once uploaded, the payload is executed, granting the attacker arbitrary code execution on the target server. The module supports multiple platforms (Java, Linux, Windows) and can deploy various payloads depending on the selected target. The exploit also includes functionality to undeploy the malicious application after execution. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and highly customizable. Several CVEs are referenced, indicating applicability to a range of Tomcat and related product vulnerabilities, primarily due to weak or default credentials and insecure configurations.
This repository contains a single Metasploit module: 'tomcat_mgr_deploy.rb', which targets Apache Tomcat servers with the Manager application exposed. The exploit requires valid credentials for the Tomcat Manager and leverages the deployment functionality to upload a malicious WAR file containing a payload (such as a reverse shell or meterpreter). The module supports multiple platforms (Java, Linux, Windows) and can automatically detect the target's platform and architecture via the /manager/serverinfo endpoint. After uploading the payload, the module triggers its execution by accessing the generated JSP endpoint, and then attempts to undeploy the application to clean up. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The main attack vector is network-based, targeting HTTP endpoints exposed by the Tomcat Manager. The module references several CVEs related to default or weak credentials in Tomcat and related products, but the core vulnerability is the ability to deploy applications via the Manager interface with valid credentials.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An insecure default-credential vulnerability in the Windows installer for Apache Tomcat. The installer assigned a blank password to the administrative user, enabling remote attackers to authenticate with administrative privileges on affected installations.
Insecure default blank password for the Tomcat administrative account in the Windows installer.
Third-party software vulnerability addressed by the HP XP P9000 Performance Advisor v5.5.1 update.
A remotely exploitable vulnerability affecting confidentiality, integrity, and availability, addressed by HP's update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.