Vulnerability Intelligence Report
Apache Shiro Code Execution Vulnerability
CVE-2016-4437
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:93.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-321 ↗CWE-321 Use of Hard-coded Cryptographic Key
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| apache | aurora | all |
| apache | shiro | all |
| redhat | fuse | 1.0 |
| redhat | jboss_middleware_text-only_advisories | 1.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
93.143%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2016-05-02T00:00:00 |
| Published | 2016-06-07T14:00:00 |
| Patch Date | 2016-06-03 |
| Last Updated | 2025-10-21T23:55:51 |
Community Chatter & Buzz