4
CVSSv2

CVE-2009-1595

Published: 11/05/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire prior to 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.

Vulnerable Product Search on Vulmon Subscribe to Product

igniterealtime openfire 3.0.1

igniterealtime openfire 3.1.0

igniterealtime openfire 3.3.0

igniterealtime openfire 3.3.2

igniterealtime openfire 3.5.1

igniterealtime openfire 3.5.2

igniterealtime openfire 2.6.2

igniterealtime openfire 3.0.0

igniterealtime openfire 3.2.3

igniterealtime openfire 3.2.4

igniterealtime openfire 3.4.4

igniterealtime openfire 3.4.5

igniterealtime openfire 3.5.0

igniterealtime openfire 3.4.2

igniterealtime openfire

igniterealtime openfire 2.6.0

igniterealtime openfire 2.6.1

igniterealtime openfire 3.2.1

igniterealtime openfire 3.2.2

igniterealtime openfire 3.4.1

igniterealtime openfire 3.4.3

igniterealtime openfire 3.6.2

igniterealtime openfire 3.6.1

igniterealtime openfire 3.1.1

igniterealtime openfire 3.2.0

igniterealtime openfire 3.3.3

igniterealtime openfire 3.4.0

igniterealtime openfire 3.6.0

igniterealtime openfire 3.6.0a

Exploits

source: wwwsecurityfocuscom/bid/34804/info Openfire is prone to a vulnerability that can permit an attacker to change the password of arbitrary users Exploiting this issue can allow the attacker to gain unauthorized access to the affected application and to completely compromise victims' accounts Versions prior to Openfire 364 are v ...