CVE Vulnerabilities

CVE-2016-4437

Published: Jun 07, 2016 | Modified: Oct 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
7.3 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

Apache Shiro before 1.2.5, when a cipher key has not been configured for the remember me feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

Affected Software

NameVendorStart VersionEnd Version
AuroraApache0.10.0 (including)0.18.1 (excluding)
ShiroApache*1.2.5 (excluding)
Red Hat JBoss A-MQ 6.3RedHat*
Red Hat JBoss Fuse 6.3RedHat*
ShiroUbuntuartful*
ShiroUbuntuesm-apps/xenial*
ShiroUbuntuupstream*
ShiroUbuntuwily*
ShiroUbuntuxenial*
ShiroUbuntuyakkety*
ShiroUbuntuzesty*

References