logo

Service Detection – Tomcat Manager, From “Info” to “Ouch”

ID: 3791a217-7dfb-595b-9fe2-1c740762623d

STIX ID: report--3791a217-7dfb-595b-9fe2-1c740762623d

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2015-07-15

Date Updated: 2026-04-27

Author: BHIS

...
...

During a penetration test the author discovered Apache Tomcat running on port 8080 where the Tomcat Manager accepted default credentials (username "admin" with a blank password). Access to the manager allowed WAR deployment and command shell access; the finding was labeled as informational by Nessus but effectively represents a critical misconfiguration that can lead to full server compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.