Back to search
CVE-2016-4437
Published: Jun 7, 2016
Modified: Oct 21, 2025
PUBLISHED
Description
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2016:2035
vendor-advisory
x_refsource_REDHAT
[[email protected]] 20171101 Apache Aurora information disclosure vulnerability
mailing-list
x_refsource_MLIST
RHSA-2016:2036
vendor-advisory
x_refsource_REDHAT
91024
vdb-entry
x_refsource_BID
20160603 [Announce] CVE-2016-4437: Apache Shiro information disclosure vulnerability
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now