← back
CVE-2009-3548

CVE-2009-3548

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 79%
from disclosure to weapon397 days
Published on NVDNov 12
1st PoC+397d
metasploitNov 9
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.