CVE-2009-1596
N/A
N/A
Summary
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.igniterealtime.org/community/message/190280
- http://www.igniterealtime.org/issues/browse/JM-1532
- http://secunia.com/advisories/34984
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50291
- http://www.securityfocus.com/bid/34804
- http://www.osvdb.org/54189
References
- http://www.igniterealtime.org/community/message/190280
- http://www.igniterealtime.org/issues/browse/JM-1532
- http://secunia.com/advisories/34984
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50291
- http://www.securityfocus.com/bid/34804
- http://www.osvdb.org/54189
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.