← Back to browse · API

CVE-2016-4437

Severity
CRITICAL
CVSS
9.8
EPSS
0.93039
Risk score
57.56
CISA KEV
Yes
PoC
No
Published
2016-06-07
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-4711, GHSA-P836-389H-J692
Products
Apache:Shiro, n/a:n/a n/a
Sources
cisa.gov CVE-2016-4437
euvd EUVD-2022-4711

Description

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

References