CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
- Affected products
- Apache Shiro, Ubuntu
- Apache Aurora
- < 0.18.1
- Apache Shiro
- < 1.2.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 93.0% (100th percentile)
- Weakness
- CWE-321
- NVD status
- Analyzed
- Published
- 2016-06-07
CVE-2016-4437 at NVD
14 known exploits for CVE-2016-4437
Proof-of-concept code and exploit modules indexed by Sploitus
cve-2016-4437
CVE-2016-4437
Awesome_shiro
CVE-2016-4437
shisoserial
CVE-2016-4437
Exploit for Use of Hard-coded Cryptographic Key in Apache Aurora
Exploit for Use of Hard-coded Cryptographic Key in Apache Aurora
Exploit for Use of Hard-coded Cryptographic Key in Apache Aurora
Exploit for Use of Hard-coded Cryptographic Key in Apache Aurora
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
Apache Shiro 1.2.4 Remote Code Execution Exploit
Apache Shiro 1.2.4 Remote Code Execution
Apache Shiro v1.2.4 Cookie RememberME Deserial RCE