Junglewise Threat Intelligence

CVE-2016-4437: Improper Access Control in Apache Shiro

CVE-2016-4437 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2022-05-14

Technologies: org.apache.shiro:shiro-core (Maven), Apache Shiro. Vendors: Apache, Maven, Red Hat.

Executive brief

Apache Shiro before 1.2.5 contains a vulnerability where a default or unconfigured cipher key for the 'remember me' feature allows for the execution of arbitrary code. Remote attackers can exploit this via unspecified request parameters to bypass access restrictions or achieve remote code execution.

Affected products

  • Apache Shiro before 1.2.5
  • Apache Aurora 0.10.0 to 0.18.1
  • Red Hat Fuse 1.0
  • Red Hat JBoss Middleware text-only advisories 1.0

Timeline

  • 2016-06-07: disclosed: Initial public disclosure via SecurityFocus and Packet Storm
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats