An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).
References
Link | Resource |
---|---|
https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt | |
https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes | Release Notes Vendor Advisory |
Configurations
History
No history.
Information
Published : 2018-03-01 21:29
Updated : 2020-10-01 17:15
NVD link : CVE-2018-7047
Mitre link : CVE-2018-7047
CVE.ORG link : CVE-2018-7047
JSON object : View
Products Affected
wowza
- streaming_engine
CWE
CWE-798
Use of Hard-coded Credentials