Re: Apache Tomcat Windows Installer Insecure Password Vulnerability

2009-12-08 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Pid, On 12/7/2009 5:23 AM, Pid wrote: > On 07/12/2009 04:53, Saw Chee Hong wrote: >> Currently mytomcat version was 5.0.27. I have check the >> ‘tomcat-users.xml’ file and it doesn’t consist the ‘admin’ user in >> the file. > > Then you are not at r

Re: Apache Tomcat Windows Installer Insecure Password Vulnerability

2009-12-07 Thread Pid
On 07/12/2009 04:53, Saw Chee Hong wrote: I seen this at one of apache website. *[Summary]* Apache Tomcat is prone to an insecure-password vulnerability in the Windows installer. The administrative password defaults to a blank password during the install process. Attackers may exploit this iss