peter bassill · operator
$ cve CVE-2016-4437 JSON

CVE-2016-4437 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 93% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS93.04% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-321
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2016-06-07
Last modified2026-06-17

CISA KEV

NameApache Shiro Code Execution Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productApache / Shiro
Ransomware usenone reported

Affected (4)

VendorProduct
apacheaurora
apacheshiro
redhatfuse
redhatjboss middleware text-only advisories

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD