References https://github.com/netbiosX/Default-Credentials/blob/master/Apache-Tomcat-Default-Passwords.mdown https://gist.github.com/0xRar/70aae102af56495b7be51486d363c4bd https://tomcat.apache.org/tomcat-9.0-doc/manager-howto.html https://stackoverflow.com/questions/3829513/what-is-the-default-username-and-password-in-tomcat https://codeahoy.com/java/tomcat-default-admin-password/ https://www.invicti.com/web-application-vulnerabilities/apache-tomcat-insecure-default-administrative-password https://docs.escape.tech/documentation/platform/vulnerabilities/tomcat_examples_login/ https://bryantson.medium.com/how-to-configure-apache-tomcat-10-first-time-with-manager-user-login-information-75ee0e92052e https://mkyong.com/tomcat/tomcat-default-administrator-password/ https://docs.unidata.ucar.edu/tds/current/userguide/tomcat_manager_app.html
Related VulnerabilitiesPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA Bypass旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞PoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default Login中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞Flowise /api/v1/loginmethod 未授权访问漏洞(CVE-2026-56270)PoClitellm-default-login: LiteLLM - Default LoginPoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCccm-detect: Clear-Com Core Configuration Manager Panel - Detect智慧物联网综合服务平台ListFileManager存在目录枚举漏洞PoCnet-vision-default-login: Net Vision UPS Monitor - Default LoginPoC3xui-default-login: 3X-UI - Default LoginPoC泛微E-cology10 /papi/passport/appnew/login/appLogin 未授权访问漏洞