Vulnerable Systems:
* IBM Rational Quality Manager
Immune Systems:
* IBM Rational Quality Manager Version 7.9.0.3 build 1046
The flaw exists within the installation of the bundled tomcat server. The default ADMIN account is improperly disabled within 'tomcat-users.xml' An account providing manager role level access is left enabled with a default password. A remote attacker can use this vulnerability to execute arbitrary code under the context of the tomcat server.