Back

MEDIUM

The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action

Published May 11, 2009

Description

The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 11, 2009
Updated Aug 7, 2024
Reserved May 11, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-R62W-X9PP-JRQP