IBM Rational Quality Manager and Rational Test Lab Manager ship with a default password for the ADMIN account in the embedded Tomcat server. This default credential allows remote attackers to authenticate as an administrator and leverage the manager role, potentially leading to arbitrary code execution on the affected system. The vulnerability is due to insecure default configuration, specifically the presence of a hardcoded or well-known password for a privileged account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module: 'tomcat_mgr_upload.rb', which targets Apache Tomcat servers with the Manager application enabled. The exploit requires valid credentials for the Tomcat Manager and leverages the /manager/html/upload endpoint to upload a malicious WAR file containing a JSP payload. Once uploaded, the payload is executed, granting the attacker arbitrary code execution on the target server. The module supports multiple platforms (Java, Linux, Windows) and can deploy various payloads depending on the selected target. The exploit also includes functionality to undeploy the malicious application after execution. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and highly customizable. Several CVEs are referenced, indicating applicability to a range of Tomcat and related product vulnerabilities, primarily due to weak or default credentials and insecure configurations.
This repository contains a single Metasploit module: 'tomcat_mgr_deploy.rb', which targets Apache Tomcat servers with the Manager application exposed. The exploit requires valid credentials for the Tomcat Manager and leverages the deployment functionality to upload a malicious WAR file containing a payload (such as a reverse shell or meterpreter). The module supports multiple platforms (Java, Linux, Windows) and can automatically detect the target's platform and architecture via the /manager/serverinfo endpoint. After uploading the payload, the module triggers its execution by accessing the generated JSP endpoint, and then attempts to undeploy the application to clean up. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The main attack vector is network-based, targeting HTTP endpoints exposed by the Tomcat Manager. The module references several CVEs related to default or weak credentials in Tomcat and related products, but the core vulnerability is the ability to deploy applications via the Manager interface with valid credentials.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.