Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
https://bugzilla.redhat.com/show_bug.cgi?id=1232366
https://access.redhat.com/errata/RHSA-2015:1592
https://access.redhat.com/errata/RHSA-2015:1591
http://theforeman.org/manuals/1.9/index.html#Releasenotesfor1.9