CVE-2016-4437

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
References
Link Resource
http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://rhn.redhat.com/errata/RHSA-2016-2035.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2036.html Third Party Advisory
http://www.securityfocus.com/archive/1/538570/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/91024 Broken Link Third Party Advisory VDB Entry
https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E Mailing List
http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html Exploit Third Party Advisory VDB Entry
http://rhn.redhat.com/errata/RHSA-2016-2035.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2036.html Third Party Advisory
http://www.securityfocus.com/archive/1/538570/100/0/threaded Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/91024 Broken Link Third Party Advisory VDB Entry
https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:aurora:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*

History

22 Oct 2025, 00:15

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437 -

21 Oct 2025, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437 -

07 Feb 2025, 14:15

Type Values Removed Values Added
CWE CWE-321

21 Nov 2024, 02:52

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html - Third Party Advisory, VDB Entry
References () http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry
References () http://rhn.redhat.com/errata/RHSA-2016-2035.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2016-2035.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2016-2036.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2016-2036.html - Third Party Advisory
References () http://www.securityfocus.com/archive/1/538570/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/538570/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/91024 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/91024 - Broken Link, Third Party Advisory, VDB Entry
References () https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E - Mailing List () https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E - Mailing List

24 Jul 2024, 17:05

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*
cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:aurora:*:*:*:*:*:*:*:*
CWE CWE-284 NVD-CWE-noinfo
CVSS v2 : 6.8
v3 : 8.1
v2 : 6.8
v3 : 9.8
References () http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html - () http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html - Third Party Advisory, VDB Entry
References () http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html - () http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry
References () http://rhn.redhat.com/errata/RHSA-2016-2035.html - () http://rhn.redhat.com/errata/RHSA-2016-2035.html - Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2016-2036.html - () http://rhn.redhat.com/errata/RHSA-2016-2036.html - Third Party Advisory
References () http://www.securityfocus.com/archive/1/538570/100/0/threaded - () http://www.securityfocus.com/archive/1/538570/100/0/threaded - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/91024 - () http://www.securityfocus.com/bid/91024 - Broken Link, Third Party Advisory, VDB Entry
References () https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E - () https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E - Mailing List
First Time Redhat
Redhat fuse
Redhat jboss Middleware Text-only Advisories
Apache aurora

Information

Published : 2016-06-07 14:06

Updated : 2025-10-22 00:15


NVD link : CVE-2016-4437

Mitre link : CVE-2016-4437

CVE.ORG link : CVE-2016-4437


JSON object : View

Products Affected

redhat

  • fuse
  • jboss_middleware_text-only_advisories

apache

  • shiro
  • aurora
CWE
NVD-CWE-noinfo CWE-321

Use of Hard-coded Cryptographic Key