PT-2016-3363 · Apache+1 · Apache Shiro+1

Published

2016-06-03

·

Updated

2025-04-03

·

CVE-2016-4437

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 1.2.5
Description The issue is related to the "remember me" feature in Apache Shiro, where the lack of a configured cipher key allows remote attackers to execute arbitrary code or bypass intended access restrictions. This can be achieved via an unspecified request parameter. The vulnerability is associated with the use of a default encryption key.
Recommendations For versions prior to 1.2.5, update to version 1.2.5 or later to resolve the issue. As a temporary workaround, consider configuring a cipher key for the "remember me" feature to prevent exploitation. Restrict access to the "remember me" functionality until a patch is applied.

Exploit

Fix

RCE

Improper Access Control

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-05609
CVE-2016-4437
GHSA-P836-389H-J692
USN-7139-1

Affected Products

Apache Shiro
Ubuntu