← Back

CVE-2009-1596

nvd nist
Published: May 11, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.

Affected (1)

Openfire
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 3.6.5

References (12)

Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
ExploitIssue TrackingPatchVendor Advisory
Source: cve@mitre.org
PatchPermissions RequiredVendor Advisory
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchPermissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkExploitPatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.