Vulnerability record · CVE-2009-3548 · published 12 November 2009
CVE-2009-3548: Apache Tomcat Windows installer ships blank admin password
Apache · Tomcat
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20 and 5.5.0 through 5.5.28 creates an administrative user with a blank default password. Any deployment that leaves this default in place exposes the Tomcat administrative interface to anyone who can reach it.
Description
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityA remotely reachable administrative interface with a blank default password gives unauthenticated attackers full admin access, and EPSS is near the top of the distribution despite no KEV listing.
What it is
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20 and 5.5.0 through 5.5.28 creates an administrative user with a blank default password. Any deployment that leaves this default in place exposes the Tomcat administrative interface to anyone who can reach it.
Impact
An attacker who reaches the administrative interface can log in with the blank password and gain the privileges of the Tomcat admin user, allowing deployment or modification of web applications and configuration.
Attack surface
Reachable over the network via the Tomcat administrative interface (CVSS vector AV:N/AC:L/Au:N), so no authentication is required when the blank password is unchanged. No user interaction is indicated by the record.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, but EPSS is very high (0.78995, 99.6th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade to a Tomcat release after 6.0.20 or 5.5.28, or apply the vendor patches referenced in the Apache Tomcat security pages for 5.x and 6.x.
- Immediately set a strong password for the Tomcat administrative user on any system installed with the affected Windows installer.
- Restrict network access to the Tomcat administrative interface to trusted management hosts only.
- Audit existing Tomcat installations for blank or default administrative credentials and remediate before exposure.
- Remove or disable the administrative web application where it is not operationally required.
Detection
- Search Tomcat configuration and user files for administrative accounts with empty or default passwords.
- Monitor authentication logs for successful logins to the Tomcat manager or admin interface from unexpected source addresses.
- Alert on deployment or modification of web applications through the Tomcat administrative interface outside change windows.
- Inventory Tomcat hosts and flag those installed via the affected Windows installer versions for credential review.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3548 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3548), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.