Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2016-4437

Apache | ShiroAdded 2021-11-03Remediation Deadline 2022-05-03

Apache Shiro Code Execution Vulnerability

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-284

References