VYPR
High severity8.8NVD Advisory· Published Apr 14, 2020· Updated Jun 17, 2026

CVE-2020-9004

CVE-2020-9004

Description

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the administration panel in order to change functionality. For example, a read-only user may activate the Java JMX port in unauthenticated mode and execute OS commands under root privileges. This issue was resolved in Wowza Streaming Engine 4.8.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:*range: <=4.8.0
    • (no CPE)range: <=4.8.0, fixed in 4.8.5
  • Wowza/Wowza Streaming Enginedescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.