Vulnerability Details CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.943
EPSS Ranking 99.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 6.8
Proposed Action
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
Ransomware Campaign
Unknown
Products affected by CVE-2016-4437
-
cpe:2.3:a:apache:aurora:0.11.0
-
cpe:2.3:a:apache:aurora:0.12.0
-
cpe:2.3:a:apache:aurora:0.13.0
-
cpe:2.3:a:apache:aurora:0.14.0
-
cpe:2.3:a:apache:aurora:0.15.0
-
cpe:2.3:a:apache:aurora:0.16.0
-
cpe:2.3:a:apache:aurora:0.17.0
-
cpe:2.3:a:apache:aurora:0.18.0
-
-
cpe:2.3:a:apache:shiro:1.1.0
-
cpe:2.3:a:apache:shiro:1.2.0
-
cpe:2.3:a:apache:shiro:1.2.1
-
cpe:2.3:a:apache:shiro:1.2.2
-
cpe:2.3:a:apache:shiro:1.2.3
-
cpe:2.3:a:apache:shiro:1.2.4
-
cpe:2.3:a:redhat:fuse:1.0
-
cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0