CVE-2009-3548: High severity tomcat vulnerability
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3548?
CVE-2009-3548 has a high severity rating due to the risk of unauthorized access to administrative functions.
How do I fix CVE-2009-3548?
To fix CVE-2009-3548, configure a strong password for the administrative user in Apache Tomcat.
What versions are affected by CVE-2009-3548?
CVE-2009-3548 affects Apache Tomcat versions 6.0.0 through 6.0.20 and 5.5.0 through 5.5.28, among others.
What impact does CVE-2009-3548 have on applications?
CVE-2009-3548 allows remote attackers to gain administrative privileges, potentially compromising the application security.
Is there a workaround for CVE-2009-3548?
A workaround for CVE-2009-3548 is to disable the default administrative user account until a secure password can be configured.