{"id":"CVE-2016-4437","aliases":["GHSA-p836-389h-j692"],"url":"https://o3.security/vulnerability/CVE-2016-4437","summary":"Improper Access Control in Apache Shiro","details":"Apache Shiro before 1.2.5, when a cipher key has not been configured for the \"remember me\" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.","published":"2016-06-07T14:06:13.247Z","modified":"2026-07-08T05:48:25.039904350Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.93039,"percentile":0.99825,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":10,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.shiro:shiro-core","fixedVersion":"1.2.5"}],"fix":null,"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4437"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-2036.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/archive/1/538570/100/0/threaded"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/91024"},{"type":"ARTICLE","url":"https://lists.apache.org/thread.html/ef3a800c7d727a00e04b78e2f06c5cd8960f09ca28c9b69d94c3c4c4%40%3Cannouncements.aurora.apache.org%3E"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:48:25.039904350Z"}}