CVE-2016-4437
07.06.2016, 14:06
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.Enginsight
Vendor | Product | Version |
---|---|---|
apache | aurora | 0.10.0 ≤ 𝑥 < 0.18.1 |
apache | shiro | 𝑥 < 1.2.5 |
redhat | fuse | 1.0 |
redhat | jboss_middleware_text-only_advisories | 1.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
shiro |
|
Common Weakness Enumeration
References