CVE-2016-4437
Apache Shiro
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
- CVSS
- 9.8
- EPSS
- 93.0% 99.8% percentile
- CISA KEV
- Listed
- Published
- 2016.06.07