EXPOSURES › CVE-2016-4437
CVE-2016-4437
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Shiro's unpatched remote code execution vulnerability allowed attackers to bypass access controls and execute arbitrary code when the 'remember me' cipher key was missing.
Apache Shiro's CVE-2016-4437 enabled remote attackers to execute code or bypass access restrictions if the 'remember me' feature lacked a cipher key. DIB organizations must ensure all Apache Shiro deployments are patched and configured correctly to prevent unauthorized access and system compromise. This failure highlights the risk of relying on unpatched components and the importance of proper cryptographic configuration.
Shame score — A known, unpatched RCE vulnerability in a widely used authentication framework that attackers could exploit to bypass access controls and execute arbitrary code.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
"Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature."