cbcvebase.
CVE-2016-4437
published 2016-06-07

CVE-2016-4437: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

Affected

9 ranges
VendorProductVersion rangeFixed in
apacheaurora>= 0.10.0 < 0.18.10.18.1
apacheshiro< 1.2.51.2.5
apacheshiro>= 0 < 1.2.5-11.2.5-1
apacheshiro>= 0 < 1.2.5-11.2.5-1
apacheshiro>= 0 < 1.2.5-11.2.5-1
debianshiro< shiro 1.2.5-1 (bookworm)shiro 1.2.5-1 (bookworm)
jeesitejeesite
redhatfuse
redhatjboss_middleware_text-only_advisories

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL