CVE-2018-7047

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
01/03/2018
Last modified:
01/10/2020

Description

An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:* 4.7.1 (excluding)