PT-2009-4083 · Ignite Realtime · Openfire

Devakrherz

·

Published

2009-05-11

·

Updated

2022-05-02

·

CVE-2009-1595

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Openfire versions prior to 3.6.4
Description: The issue allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd change action. This is due to a flaw in the jabber:iq:auth implementation in IQAuthHandler.java.
Recommendations: For versions prior to 3.6.4, update to version 3.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the passwd change action to prevent unauthorized password changes.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1595
GHSA-R62W-X9PP-JRQP

Affected Products

Openfire