CVE-2009-1596
MEDIUMIgniterealtime Openfire < 3.6.5 - Authentication Bypass
Title source: ruleDescription
Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.
References (6)
Scores
CVSS v3
6.5
EPSS
0.0035
EPSS Percentile
57.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
igniterealtime/openfire
< 3.6.5
Timeline
Published
May 11, 2009
Tracked Since
Feb 18, 2026