CVE-2018-7047

CRITICAL

Wowza Streaming Engine < 4.7.1 - Use of Hard-coded Credentials in MBeans Server

Title source: llm
STIX 2.1

Description

An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0236
EPSS Percentile 81.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
wowza/streaming_engine < 4.7.1
Published Mar 01, 2018
Tracked Since Feb 18, 2026