Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
References
Link | Resource |
---|---|
http://secunia.com/advisories/34984 | Broken Link Vendor Advisory |
http://www.igniterealtime.org/community/message/190280 | Exploit Issue Tracking Patch Vendor Advisory |
http://www.igniterealtime.org/issues/browse/JM-1532 | Patch Permissions Required Vendor Advisory |
http://www.osvdb.org/54189 | Broken Link |
http://www.securityfocus.com/bid/34804 | Broken Link Exploit Patch Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50291 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2009-05-11T14:02:00
Updated: 2017-08-16T14:57:01
Reserved: 2009-05-11T00:00:00
Link: CVE-2009-1596
JSON object: View
NVD Information
Status : Analyzed
Published: 2009-05-11T14:30:00.343
Modified: 2024-02-13T17:43:58.267
Link: CVE-2009-1596
JSON object: View
Redhat Information
No data.
CWE