vendor:
Tomcat
by:
jduck
7
CVSS
HIGH
Authentication Bypass
287, 287, 287, 287, 287, 287, 287, 287, 287, 287, 287, 287, 287, 287, 287, 287
CWE
Product Name: Tomcat
Affected Version From: Automatic
Affected Version To: Automatic
Patch Exists: YES
Related CWE: CVE-2009-3843, OSVDB-60317, CVE-2009-4189, OSVDB-60670, CVE-2009-4188, BID-38084, CVE-2010-0557, CVE-2010-4094, CVE-2009-3548, OSVDB-60176, CVE-2009-3547, OSVDB-60175, CVE-2009-4186, OSVDB-60668, CVE-2009-4187, OSVDB-60669, CVE-2009-4184, OSVDB-60666, CVE-2009-4185, OSVDB-60667
CPE: a:apache:tomcat
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apache-tomcat-default-ovwebusr-password/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0987/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0986/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0865/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0770/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0880/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0768/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0786/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0807/, https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2009-3548/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2009-3548/, https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0003-cve-2009-3548/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1692/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-3547/, https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0010-cve-2009-3547/, https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0009-1-service-console-update-cve-2009-3547/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-3547/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1540/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1587/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1672/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1550/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2009-4184/, https://www.rapid7.com/db/vulnerabilities/hpsmh-cve-2009-4185/
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=29880, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=62973, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/nessus-plugin-library/?id=47023, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=62579, https://www.infosecmatter.com/nessus-plugin-library/?id=62580, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=34970, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/nessus-plugin-library/?id=34970, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=34970, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=156264, https://www.infosecmatter.com/nessus-plugin-library/?id=128477, https://www.infosecmatter.com/nessus-plugin-library/?id=127058, https://www.infosecmatter.com/nessus-plugin-library/?id=34970, https://www.infosecmatter.com/nessus-plugin-library/?id=89674, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/nessus-plugin-library/?id=51197, https://www.infosecmatter.com/nessus-plugin-library/?id=51750, https://www.infosecmatter.com/nessus-plugin-library/?id=64843, https://www.infosecmatter.com/nessus-plugin-library/?id=76303, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/tomcat_mgr_login, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_upload, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/http/tomcat_mgr_deploy, https://www.infosecmatter.com/nessus-plugin-library/?id=44993, https://www.infosecmatter.com/nessus-plugin-library/?id=42357, https://www.infosecmatter.com/nessus-plugin-library/?id=79470, https://www.infosecmatter.com/nessus-plugin-library/?id=42360, https://www.infosecmatter.com/nessus-plugin-library/?id=67067, https://www.infosecmatter.com/nessus-plugin-library/?id=42358, https://www.infosecmatter.com/nessus-plugin-library/?id=63902, https://www.infosecmatter.com/nessus-plugin-library/?id=42812, https://www.infosecmatter.com/nessus-plugin-library/?id=89737, https://www.infosecmatter.com/nessus-plugin-library/?id=63910, https://www.infosecmatter.com/nessus-plugin-library/?id=63402, https://www.infosecmatter.com/nessus-plugin-library/?id=62579, https://www.infosecmatter.com/nessus-plugin-library/?id=62580, https://www.infosecmatter.com/nessus-plugin-library/?id=63402, https://www.infosecmatter.com/nessus-plugin-library/?id=62579, https://www.infosecmatter.com/nessus-plugin-library/?id=62580, https://www.infosecmatter.com/nessus-plugin-library/?id=63402, https://www.infosecmatter.com/nessus-plugin-library/?id=62579, https://www.infosecmatter.com/nessus-plugin-library/?id=62580, https://www.infosecmatter.com/nessus-plugin-library/?id=46015, https://www.infosecmatter.com/nessus-plugin-library/?id=63402, https://www.infosecmatter.com/nessus-plugin-library/?id=47539, https://www.infosecmatter.com/nessus-plugin-library/?id=62579, https://www.infosecmatter.com/nessus-plugin-library/?id=62580
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Java, Linux, Windows
2009
Apache Tomcat Manager Application Deployer Authenticated Code Execution
This module can be used to execute a payload on Apache Tomcat servers that have an exposed 'manager' application. The payload is uploaded as a WAR archive containing a jsp application using a PUT request.
Mitigation:
Ensure that the Tomcat Manager application is not exposed to the public internet, and that strong passwords are used for all accounts with access to the application.