CVE-2016-4437
EUVD-2022-471107.06.2016, 14:06
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | aurora | 0.10.0 ≤ 𝑥 < 0.18.1 |
| apache | shiro | 𝑥 < 1.2.5 |
| redhat | fuse | 1.0 |
| redhat | jboss_middleware_text-only_advisories | 1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| shiro |
|
Common Weakness Enumeration
References