CVE-2016-4437
07.06.2016, 14:06
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apache | aurora | 0.10.0 ≤ 𝑥 < 0.18.1 |
| apache | shiro | 𝑥 < 1.2.5 |
| redhat | fuse | 1.0 |
| redhat | jboss_middleware_text-only_advisories | 1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| shiro |
|
Common Weakness Enumeration
References