CVE-2018-7047: Critical severity Wowza Streaming Engine vulnerability
An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7047 vulnerability?
CVE-2018-7047 is a vulnerability in Wowza Streaming Engine before version 4.7.1 that allows unauthorized access to the file system via JMX using default credentials, potentially leading to remote code execution.
How severe is the CVE-2018-7047 vulnerability?
The severity of CVE-2018-7047 is rated as critical with a CVSS score of 9.8.
How can I fix the CVE-2018-7047 vulnerability?
To fix the CVE-2018-7047 vulnerability, update Wowza Streaming Engine to version 4.7.1 or later.
Where can I find more information about the CVE-2018-7047 vulnerability?
For more information about CVE-2018-7047, you can refer to the CVE-2018-7047.txt file at https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt and the Wowza Streaming Engine 4.7.1 release notes at https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes.