Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
References
Link | Resource |
---|---|
http://www.igniterealtime.org/community/message/190280 | Exploit Patch Vendor Advisory |
http://secunia.com/advisories/34984 | Vendor Advisory |
http://www.securityfocus.com/bid/34804 | Exploit Patch |
http://www.igniterealtime.org/issues/browse/JM-1532 | Patch Vendor Advisory |
http://www.osvdb.org/54189 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50291 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-05-11 07:30
Updated : 2017-08-16 18:30
NVD link : CVE-2009-1596
Mitre link : CVE-2009-1596
JSON object : View
CWE
CWE-16
Configuration
Products Affected
igniterealtime
- openfire