Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-321 | |
| Metrics |
kev
|
Wed, 14 Aug 2024 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published: 2016-06-07T14:00:00.000Z
Updated: 2025-10-21T23:55:51.717Z
Reserved: 2016-05-02T00:00:00.000Z
Link: CVE-2016-4437
Updated: 2024-08-06T00:32:24.897Z
Status : Deferred
Published: 2016-06-07T14:06:13.247
Modified: 2025-10-22T00:15:52.760
Link: CVE-2016-4437