CVE-2010-4094
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 64.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 64.50% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- ibm/rational quality manager · ibm/rational test lab manager
- Source
- cve@mitre.org
References
- http://download4.boulder.ibm.com/sar/CMA/RAA/013m6/0/UpdateLog.txt
- http://osvdb.org/69008
- http://secunia.com/advisories/41784
- http://securitytracker.com/id?1024601
- http://www.securityfocus.com/bid/44172
- http://www.vupen.com/english/advisories/2010/2732Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-214/
- http://download4.boulder.ibm.com/sar/CMA/RAA/013m6/0/UpdateLog.txt
- http://osvdb.org/69008
- http://secunia.com/advisories/41784
- http://securitytracker.com/id?1024601
- http://www.securityfocus.com/bid/44172
- http://www.vupen.com/english/advisories/2010/2732Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-10-214/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.