CVE-2016-4437: Apache Shiro Code Execution Vulnerability

Published Jun 7, 2016
·
Updated

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

Other sources

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

CISA

Affected Software

8 affected componentsFixes available
Apache Shiro<=1.2.4
maven/org.apache.shiro:shiro-core<=1.2.4
1.2.5
Apache Shiro
debian/shiro
1.3.2-4+deb11u11.3.2-5
Apache Aurora>=0.10.0<0.18.1
Apache Shiro<1.2.5
redhat Fuse=1.0
redhat Jboss Middleware Text-only Advisories Middleware=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.apache.shiro:shiro-core to a version that resolves this vulnerability.

    Fixed in 1.2.5
  2. Upgrade

    Upgrade debian/shiro to a version that resolves this vulnerability.

    Fixed in 1.3.2-4+deb11u1Fixed in 1.3.2-5
  3. Upgrade

    Upgrade debian/shiro to a version that resolves this vulnerability.

    Fixed in 1.3.2-4+deb11u1
  4. Upgrade

    Upgrade debian/shiro to a version that resolves this vulnerability.

    Fixed in 1.3.2-5
  5. Configuration

    Ensure a cipher key is configured for Shiro's 'remember me' feature (do not leave the cipher key unset). Set a secure, non-empty cipher key in your Shiro configuration so the remember-me functionality is not operating without a cipher key.

    Apache Shiro 'remember me' feature cipher key = configured (non-empty, secret key)

Event History

Jun 7, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:06 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
May 14, 2022
Advisory Published
via GitHub·02:46 AM
Dec 5, 2024
Data Sourced
via Launchpad·06:00 PM
Description
Dec 9, 2024
Data Sourced
via Ubuntu·05:59 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-4437?

CVE-2016-4437 is classified as critical due to its potential to allow remote code execution.

2

How do I fix CVE-2016-4437?

To fix CVE-2016-4437, upgrade Apache Shiro to version 1.2.5 or later.

3

What versions of Apache Shiro are affected by CVE-2016-4437?

CVE-2016-4437 affects Apache Shiro versions prior to 1.2.5.

4

What can be exploited in CVE-2016-4437?

CVE-2016-4437 can be exploited to execute arbitrary code or bypass access restrictions without a configured cipher key.

5

Is CVE-2016-4437 limited to a specific platform?

CVE-2016-4437 affects the Apache Shiro framework across various platforms that utilize the vulnerable versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203