QID 375677
Date Published: 2021-07-06
QID 375677: Wowza Streaming Engine Insecure Permissions vulnerability
Wowza Streaming Engine is a unified streaming media server software developed by Wowza Media Systems.
CVE-2018-7047: The file system may be read and written to via JMX using the default JMX credentials.
Affected Products:
Wowza Streaming Engine prior to version 4.7.1
QID Detection Logic (authenticated):
Operating Systems: Windows
The QID checks the registry "HKLM\SOFTWARE\Wowza Media Systems\Wowza Streaming Engine" to retrieve the version and location of Wowza Streaming Engine.
Successful exploitation of this vulnerability may allow an attacker to read and write arbitrary files to the targeted system.
Solution
Refer to Wowza Streaming Engine 4.7.1 release notes for more information.
Vendor References
- Wowza Streaming Engine 4.7.1 Release Notes -
www.wowza.com/docs/wowza-streaming-engine-4-7-1-release-notes
CVEs related to QID 375677
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Wowza Streaming Engine 4.7.1 Release Notes |
|