Vulnerability record · CVE-2010-0557 · published 5 February 2010
CVE-2010-0557: IBM Cognos Express hardcoded Tomcat Manager credentials
Ibm · Cognos Express
IBM Cognos Express 9.0 ships with hardcoded credentials that grant unspecified access to the Tomcat Manager component. Because the credentials are static and embedded, any remote attacker who knows or guesses them can reach the manager interface without legitimate authorization. The same flaw also allows a denial of service against the affected service.
Description
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable hardcoded credentials with a high CVSS 2.0 score of 7.5 and very high EPSS percentile warrant prompt remediation despite no KEV listing.
What it is
IBM Cognos Express 9.0 ships with hardcoded credentials that grant unspecified access to the Tomcat Manager component. Because the credentials are static and embedded, any remote attacker who knows or guesses them can reach the manager interface without legitimate authorization. The same flaw also allows a denial of service against the affected service.
Impact
An attacker gains unauthorized access to the Tomcat Manager, which can expose deployed applications and allow manipulation or shutdown of the service, plus the ability to cause a denial of service.
Attack surface
Reachable over the network through the exposed Tomcat Manager interface, with no authentication beyond the hardcoded credentials and no user interaction required, per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is 0.51069 (98.9th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the IBM vendor fix referenced in the advisory (swg21419179) or upgrade Cognos Express to a release that removes the hardcoded credentials.
- Change or disable the default Tomcat Manager credentials and restrict manager access to trusted administrative networks.
- Block external access to the Tomcat Manager endpoint at the firewall or reverse proxy.
- Audit Cognos Express deployments for the default Tomcat Manager account and remove or rotate it.
- Monitor the Tomcat Manager for unexpected deployments or configuration changes.
Detection
- Review Tomcat Manager access logs for logins or requests from unexpected source IPs.
- Alert on successful authentication to the manager application using default or shared credentials.
- Monitor for unexpected WAR deployments or application restarts on the Cognos Express Tomcat instance.
- Watch for availability drops or service restarts consistent with a denial-of-service attempt against Tomcat.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://secunia.com/advisories/38457 | Vendor Advisory |
| http://www-01.ibm.com/support/docview.wss?uid=swg21419179 | Vendor Advisory |
| http://www.osvdb.org/62118 | |
| http://www.securityfocus.com/bid/38084 | |
| http://www.vupen.com/english/advisories/2010/0297 | Vendor Advisory |
| http://secunia.com/advisories/38457 | Vendor Advisory |
| http://www-01.ibm.com/support/docview.wss?uid=swg21419179 | Vendor Advisory |
| http://www.osvdb.org/62118 | |
| http://www.securityfocus.com/bid/38084 | |
| http://www.vupen.com/english/advisories/2010/0297 | Vendor Advisory |
Track CVE-2010-0557 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.