PT-2009-4083 · Ignite Realtime · Openfire
Devakrherz
·
Published
2009-05-11
·
Updated
2022-05-02
·
CVE-2009-1595
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Openfire versions prior to 3.6.4
Description:
The issue allows remote authenticated users to change the passwords of arbitrary accounts via a modified
username element in a passwd change action. This is due to a flaw in the jabber:iq:auth implementation in IQAuthHandler.java.Recommendations:
For versions prior to 3.6.4, update to version 3.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the
passwd change action to prevent unauthorized password changes.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfire