Vulnerabilities > CVE-2010-4094 - Credentials Management vulnerability in IBM products

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
ibm
CWE-255
nessus
exploit available
metasploit

Summary

The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.

Vulnerable Configurations

Part Description Count
Application
Ibm
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionApache Tomcat Manager Application Deployer Authenticated Code Execution. CVE-2009-3548,CVE-2009-3843,CVE-2009-4188,CVE-2009-4189,CVE-2010-0557,CVE-2010-4094....
idEDB-ID:16317
last seen2016-02-01
modified2010-12-14
published2010-12-14
reportermetasploit
sourcehttps://www.exploit-db.com/download/16317/
titleApache Tomcat Manager Application Deployer Authenticated Code Execution

Metasploit

Nessus

NASL familyWeb Servers
NASL idTOMCAT_MANAGER_COMMON_CREDS.NASL
descriptionNessus was able to gain access to the Manager web application for the remote Tomcat server using a known set of credentials. A remote attacker can exploit this issue to install a malicious application on the affected server and run arbitrary code with Tomcat
last seen2020-06-01
modified2020-06-02
plugin id34970
published2008-11-26
reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/34970
titleApache Tomcat Manager Common Administrative Credentials

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/125021/tomcat_mgr_upload.rb.txt
idPACKETSTORM:125021
last seen2016-12-05
published2014-02-01
reporterrangercha
sourcehttps://packetstormsecurity.com/files/125021/Apache-Tomcat-Manager-Code-Execution.html
titleApache Tomcat Manager Code Execution

Saint

bid44172
descriptionIBM Rational Quality Manager and Test Lab Manager Policy Bypass
titleibm_rational_quality_manager_default_credentials
typeremote