{"id":"CVE-2016-4437","details":"Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.","aliases":["GHSA-p836-389h-j692"],"modified":"2026-07-08T05:48:25.039904350Z","published":"2016-06-07T14:06:13.247Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"}],"source":"CPE_STRING","vendor_product":"redhat:fuse","cpes":["cpe:2.3:a:redhat:fuse:1.0:*:*:*:*:*:*:*"]},{"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_middleware_text-only_advisories","cpes":["cpe:2.3:a:redhat:jboss_middleware_text-only_advisories:1.0:*:*:*:*:middleware:*:*"]}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2036.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/archive/1/538570/100/0/threaded"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91024"},{"type":"ARTICLE","url":"https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/aurora","events":[{"introduced":"fc8697aa0fee97cb587f21334ca58b40546f3e76"},{"fixed":"b009191cf66aa73c5ed85ccfd5d5e322efa11c74"}],"database_specific":{"extracted_events":[{"introduced":"0.10.0"},{"fixed":"0.18.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:aurora:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4437.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/apache/shiro","events":[{"introduced":"0"},{"fixed":"bf1e04fca099ca6fd1a9a16da1aea04a5bb8f404"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.2.5"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:shiro:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4437.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}