CVE-2009-1595
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authentic
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
MEDIUM · CVSS 4
EPSS 0.08841
Schedule remediation
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0