Back to search
CVE-2009-1595
Published: May 11, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2009-1237
vdb-entry
x_refsource_VUPEN
http://www.igniterealtime.org/builds/openfire/docs/latest/changelog.html
x_refsource_CONFIRM
54189
vdb-entry
x_refsource_OSVDB
http://www.igniterealtime.org/community/message/190280
x_refsource_CONFIRM
http://www.igniterealtime.org/issues/browse/JM-1531
x_refsource_CONFIRM
34804
vdb-entry
x_refsource_BID
34976
third-party-advisory
x_refsource_SECUNIA
openfire-jabberiqauth-security-bypass(50292)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now