target entity

Shiro

1 source-linked records in the current knowledge graph.

high

CVE-2016-4437: Apache Shiro Code Execution Vulnerability

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature. Required action: Apply updates per vendor instructions.

CVE-2016-4437EPSS 93.0%ApacheShiro
CISA KEV ↗ · unattributed attribution