An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).
References
Link | Resource |
---|---|
https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes | Release Notes Vendor Advisory |
https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt |
Configurations
Information
Published : 2018-03-01 13:29
Updated : 2020-10-01 10:15
NVD link : CVE-2018-7047
Mitre link : CVE-2018-7047
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
wowza
- streaming_engine