A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and previous versions allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges. This issue was resolved in Wowza Streaming Engine 4.8.5.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wowza streaming engine |