Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-321 | |
Metrics |
kev
|
Wed, 14 Aug 2024 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-07T13:29:17.376Z
Reserved: 2016-05-02T00:00:00.000Z
Link: CVE-2016-4437

Updated: 2024-08-06T00:32:24.897Z

Status : Modified
Published: 2016-06-07T14:06:13.247
Modified: 2025-02-07T14:15:41.510
Link: CVE-2016-4437
