The jabber:iq:auth
implementation in IQAuthHandler.java
in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change
action.
www.igniterealtime.org/community/message/190280
download.igniterealtime.org/openfire/docs/latest/changelog.html#3.6.4
exchange.xforce.ibmcloud.com/vulnerabilities/50292
github.com/igniterealtime/Openfire
github.com/igniterealtime/Openfire/commit/97e1f08cf72e430f5cca5ba94cd20703dadb5ce5
nvd.nist.gov/vuln/detail/CVE-2009-1595
web.archive.org/web/20090518061336/www.igniterealtime.org/issues/browse/JM-1531
web.archive.org/web/20140901211944/www.securityfocus.com/bid/34804