{"api_version":"1","generated_at":"2026-07-23T19:55:42+00:00","cve":"CVE-2018-7047","urls":{"html":"https://cve.report/CVE-2018-7047","api":"https://cve.report/api/cve/CVE-2018-7047.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-7047","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-7047"},"summary":{"title":"CVE-2018-7047","description":"An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-03-01 21:29:00","updated_at":"2020-10-01 17:15:00"},"problem_types":["CWE-798"],"metrics":[],"references":[{"url":"https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes","name":"https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Wowza Streaming Engine 4.7.1 Release Notes | Wowza Docs & APIs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt","name":"https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt","refsource":"MISC","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-7047","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7047","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"7047","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wowza","cpe5":"streaming_engine","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"7047","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wowza","cpe5":"streaming_engine","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2018-7047","qid":"375677","title":"Wowza Streaming Engine Insecure Permissions vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-7047","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes","refsource":"MISC","url":"https://www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes"},{"refsource":"MISC","name":"https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt","url":"https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2018-7047.txt"}]}},"nvd":{"publishedDate":"2018-03-01 21:29:00","lastModifiedDate":"2020-10-01 17:15:00","problem_types":["CWE-798"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:*","versionEndExcluding":"4.7.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"7047","Ordinal":"123282","Title":"CVE-2018-7047","CVE":"CVE-2018-7047","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"7047","Ordinal":"1","NoteData":"An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well).","Type":"Description","Title":null},{"CveYear":"2018","CveId":"7047","Ordinal":"2","NoteData":"2018-03-01","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"7047","Ordinal":"3","NoteData":"2020-10-01","Type":"Other","Title":"Modified"}]}}}