Skip to content
COOEY

EXPOSURES › CVE-2016-4437

CVE-2016-4437

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-4437 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Apache Shiro's unpatched remote code execution vulnerability allowed attackers to bypass access controls and execute arbitrary code when the 'remember me' cipher key was missing.

Apache Shiro's CVE-2016-4437 enabled remote attackers to execute code or bypass access restrictions if the 'remember me' feature lacked a cipher key. DIB organizations must ensure all Apache Shiro deployments are patched and configured correctly to prevent unauthorized access and system compromise. This failure highlights the risk of relying on unpatched components and the importance of proper cryptographic configuration.

Shame score — A known, unpatched RCE vulnerability in a widely used authentication framework that attackers could exploit to bypass access controls and execute arbitrary code.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; sources are CVE databases with no commentary on Apache's handling.
cooey ↗ neutral +0.00
Neutral; NVD provides factual CVE data without sentiment.
"Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature."
www.cvefind.com ↗ neutral +0.00
Neutral; CVE Find is a database listing with no commentary.
NVD ↗ neutral +0.00
Neutral; NVD page shows only site warnings and navigation.
app.opencve.io ↗ neutral +0.00
Neutral; OpenCVE is a search database with no commentary.
SentinelOne ↗ neutral +0.00
Neutral; SentinelOne page shows only product marketing.
sam.gov ↗ neutral +0.00
Neutral; SAM.gov page shows only contract details.
cve.akaoma.com ↗ neutral +0.00
Neutral; Akaoma page shows only a dashboard header.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.