Beveiligingsadvies

CVE-2009-1595

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2009-05-11 14:02:00
Laatst bijgewerkt 2024-08-07 05:20:34
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.