PT-2016-3363 · Apache+1 · Apache Shiro+1

CVE-2016-4437

·

Publicado

2016-06-03

·

Atualizado

2026-09-07

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Shiro versions prior to 1.2.5
Description The issue is related to the "remember me" feature in Apache Shiro, where the lack of a configured cipher key allows remote attackers to execute arbitrary code or bypass intended access restrictions. This can be achieved via an unspecified request parameter. The vulnerability is associated with the use of a default encryption key.
Recommendations For versions prior to 1.2.5, update to version 1.2.5 or later to resolve the issue. As a temporary workaround, consider configuring a cipher key for the "remember me" feature to prevent exploitation. Restrict access to the "remember me" functionality until a patch is applied.

Exploit

Correção

RCE

Improper Authentication

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-05609
CVE-2016-4437
GHSA-P836-389H-J692
USN-7139-1

Produtos afetados

Apache Shiro
Ubuntu