Skip to content

Tomcat Admin interface publicly exposed with weak creds (and other security issues) #11

Description

@ElColmo

The Tomcat Admin interface installed and used by Benchmark is exposed on all interfaces, with weak credentials "admin" (with no password). This exposes the webapp, and the underlying host to total compromise by any attacker on the network.

The Tomcat instance is unhardened, and has various other issues as well.

I suggest the following changes:

  1. Configure the underlying Tomcat 8 instance to listen only on 127.0.0.1
  2. Remove the following administrative consoles, which are not required
  • /manager
  • /host-manager
    3) Change the default Tomcat users configured in tomcat-users.xml (or simply remove all users, since they do not appear to be required)
    4) Remove sample.war (and the examples folder in its entirety)
    5) Remove the installed documentation folder
    6) If deploying a Tomcat instance with Benchmark, follow the CIS Tomcat Hardening guidelines.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions