Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
References
Link Resource
http://secunia.com/advisories/34984 Broken Link Vendor Advisory
http://www.igniterealtime.org/community/message/190280 Exploit Issue Tracking Patch Vendor Advisory
http://www.igniterealtime.org/issues/browse/JM-1532 Patch Permissions Required Vendor Advisory
http://www.osvdb.org/54189 Broken Link
http://www.securityfocus.com/bid/34804 Broken Link Exploit Patch Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/50291 Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-05-11T14:02:00

Updated: 2017-08-16T14:57:01

Reserved: 2009-05-11T00:00:00


Link: CVE-2009-1596

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2009-05-11T14:30:00.343

Modified: 2024-02-13T17:43:58.267


Link: CVE-2009-1596

JSON object: View

cve-icon Redhat Information

No data.

CWE