Apache Tomcat Windows Installer Insecure Password Vulnerability
BID:36954
Info
Apache Tomcat Windows Installer Insecure Password Vulnerability
| Bugtraq ID: | 36954 |
| Class: | Design Error |
| CVE: |
CVE-2009-3548 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2009 12:00AM |
| Updated: | Feb 27 2014 12:31PM |
| Credit: | David Horheim |
| Vulnerable: |
VMWare vCenter 4.0 VMWare ESX Server 4.1 VMWare ESX Server 4.0 Sun Solaris 10 IBM WebSphere Application Server Community Edition 2.0 1 IBM WebSphere Application Server Community Edition 2.0 HP Performance Manager 8.21 HP Performance Manager 8.20 HP Performance Manager 8.10 HP OpenVMS Secure Web Server 7.3 -2 HP OpenVMS Secure Web Server 7.3 -1 HP OpenVMS Secure Web Server 7.3 HP OpenVMS Secure Web Server 7.2 -2 HP OpenVMS Secure Web Server 1.2 HP OpenVMS Secure Web Server 1.1 -1 HP OpenVMS Secure Web Server 2.2 HP OpenVMS Secure Web Server 2.1-1 HP HP-UX Web Server Suite 3.22 HP HP-UX Web Server Suite 3.21 HP HP-UX Web Server Suite 3.18 HP HP-UX Web Server Suite 3.17 HP HP-UX Web Server Suite 3.10 HP HP-UX Web Server Suite 2.31 HP HP-UX B.11.31 HP HP-UX B.11.11 Apache Software Foundation Tomcat 6.0.20 Apache Software Foundation Tomcat 6.0.18 Apache Software Foundation Tomcat 6.0.16 Apache Software Foundation Tomcat 6.0.15 Apache Software Foundation Tomcat 6.0.14 Apache Software Foundation Tomcat 6.0.13 Apache Software Foundation Tomcat 6.0.12 Apache Software Foundation Tomcat 6.0.11 Apache Software Foundation Tomcat 6.0.10 Apache Software Foundation Tomcat 6.0.9 Apache Software Foundation Tomcat 6.0.8 Apache Software Foundation Tomcat 6.0.7 Apache Software Foundation Tomcat 6.0.6 Apache Software Foundation Tomcat 6.0.5 Apache Software Foundation Tomcat 6.0.4 Apache Software Foundation Tomcat 6.0.3 Apache Software Foundation Tomcat 6.0.2 Apache Software Foundation Tomcat 6.0.1 Apache Software Foundation Tomcat 6.0 Apache Software Foundation Tomcat 5.5.28 Apache Software Foundation Tomcat 5.5.27 Apache Software Foundation Tomcat 5.5.26 Apache Software Foundation Tomcat 5.5.25 Apache Software Foundation Tomcat 5.5.24 Apache Software Foundation Tomcat 5.5.23 Apache Software Foundation Tomcat 5.5.22 Apache Software Foundation Tomcat 5.5.21 Apache Software Foundation Tomcat 5.5.20 Apache Software Foundation Tomcat 5.5.19 Apache Software Foundation Tomcat 5.5.18 Apache Software Foundation Tomcat 5.5.17 Apache Software Foundation Tomcat 5.5.16 Apache Software Foundation Tomcat 5.5.15 Apache Software Foundation Tomcat 5.5.14 Apache Software Foundation Tomcat 5.5.13 Apache Software Foundation Tomcat 5.5.12 Apache Software Foundation Tomcat 5.5.11 Apache Software Foundation Tomcat 5.5.10 Apache Software Foundation Tomcat 5.5.9 Apache Software Foundation Tomcat 5.5.8 Apache Software Foundation Tomcat 5.5.7 Apache Software Foundation Tomcat 5.5.6 Apache Software Foundation Tomcat 5.5.5 Apache Software Foundation Tomcat 5.5.4 Apache Software Foundation Tomcat 5.5.3 Apache Software Foundation Tomcat 5.5.2 Apache Software Foundation Tomcat 5.5.1 Apache Software Foundation Tomcat 5.5 |
| Not Vulnerable: |
VMWare ESX Server 4.1 ESX410-201101201 IBM WebSphere Application Server Community Edition 2.1.1.4 |
Discussion
Apache Tomcat Windows Installer Insecure Password Vulnerability
Apache Tomcat is prone to an insecure-password vulnerability.
Attackers may exploit this issue to obtain administrative access to the application. Other attacks may also be possible.
The following are vulnerable:
Tomcat 6.0.0 through 6.0.20
Tomcat 5.5.0 through 5.5.28
Unsupported versions in the 3.x, 4.x, 4.1.x, and 5.0.x branches may also be affected.
Apache Tomcat is prone to an insecure-password vulnerability.
Attackers may exploit this issue to obtain administrative access to the application. Other attacks may also be possible.
The following are vulnerable:
Tomcat 6.0.0 through 6.0.20
Tomcat 5.5.0 through 5.5.28
Unsupported versions in the 3.x, 4.x, 4.1.x, and 5.0.x branches may also be affected.
Exploit / POC
Apache Tomcat Windows Installer Insecure Password Vulnerability
An attacker can exploit this issue with readily available tools.
An attacker can exploit this issue with readily available tools.
Solution / Fix
Apache Tomcat Windows Installer Insecure Password Vulnerability
Solution:
Updates are available. Please see the references for details.
HP Performance Manager 8.10
HP Performance Manager 8.21
HP Performance Manager 8.20
Solution:
Updates are available. Please see the references for details.
HP Performance Manager 8.10
-
HP HPPM8CPI_00001
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPL_00001
Linux
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPP_00001
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPS_00001
Solaris
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPW_00001
Windows
http://support.openview.hp.com/selfsolve/patches
HP Performance Manager 8.21
-
HP HPPM8CPI_00001
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPL_00001
Linux
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPP_00001
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPS_00001
Solaris
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPW_00001
Windows
http://support.openview.hp.com/selfsolve/patches
HP Performance Manager 8.20
-
HP HPPM8CPI_00001
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPL_00001
Linux
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPP_00001
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPS_00001
Solaris
http://support.openview.hp.com/selfsolve/patches -
HP HPPM8CPW_00001
Windows
http://support.openview.hp.com/selfsolve/patches
References
Apache Tomcat Windows Installer Insecure Password Vulnerability
References:
References:
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat 6.x vulnerabilities (Apache)
- Revision 834047 (Apache Software Foundation)
- Tomcat Homepage (Apache Software Foundation)
- WebSphere Application Server Community Edition V2.1.1.4 - CHANGES.txt (IBM)
- [SECURITY] CVE-2009-3548 Apache Tomcat Windows Installer insecure default admini (Mark Thomas
)