Service Detection – Tomcat Manager, From “Info” to “Ouch”
ID: 3791a217-7dfb-595b-9fe2-1c740762623d
STIX ID: report--3791a217-7dfb-595b-9fe2-1c740762623d
Feed Name: Black Hills Infosec Blog
Threat Score
During a penetration test the author discovered Apache Tomcat running on port 8080 where the Tomcat Manager accepted default credentials (username "admin" with a blank password). Access to the manager allowed WAR deployment and command shell access; the finding was labeled as informational by Nessus but effectively represents a critical misconfiguration that can lead to full server compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
