CVE-2009-1596

MEDIUM

Igniterealtime Openfire < 3.6.5 - Authentication Bypass

Title source: rule

Description

Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.

Scores

CVSS v3 6.5
EPSS 0.0035
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-287
Status draft

Affected Products (1)

igniterealtime/openfire < 3.6.5

Timeline

Published May 11, 2009
Tracked Since Feb 18, 2026