PoC Index

CVE-2016-4437

KEVCRITICAL 9.8EPSS 93.0%

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
93.04% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2021-11-03
Nuclei
high · CWE-284
Published
2016-06-07
Updated
2025-10-21

Proof-of-concept exploits (6)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

Vulhub environments (1)

References

Related