RaqibCTI
CVE

CVE-2016-4437

P2
Apache Shiro Code Execution Vulnerability
Apache · Shiro
Date added (CISA)
2021-11-03
Remediation due
2022-05-03
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

Source: NVD ↗ · CISA KEV Catalog ↗