CVE-2009-1595: Medium severity igniterealtime Openfire vulnerability
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwdchange action.
Other sources
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwdchange action.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1595?
CVE-2009-1595 is considered a critical vulnerability as it allows remote authenticated users to change passwords of arbitrary accounts.
How do I fix CVE-2009-1595?
To fix CVE-2009-1595, upgrade your Ignite Realtime Openfire to version 3.6.4 or later.
Which versions of Openfire are affected by CVE-2009-1595?
Affected versions include Openfire from 3.0.0 up to 3.6.3.
What impact does CVE-2009-1595 have on system security?
CVE-2009-1595 allows an authenticated user to gain unauthorized access to other user accounts by changing their passwords.
Is CVE-2009-1595 exploitable without authentication?
No, CVE-2009-1595 requires that the attacker be an authenticated user to exploit the vulnerability.