CVE-2016-4437: Apache Shiro Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 93% chance of exploitation in the next 30 days.

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

Affected products

  • Apache Aurora: from 0.10.0, before 0.18.1 (fixed in 0.18.1)
  • Apache Shiro: before 1.2.5 (fixed in 1.2.5)
  • Red Hat Fuse: version 1.0 only
  • Red Hat JBoss Middleware Text-Only Advisories: version 1.0 only

Published 2016-06-07. Last modified 2026-06-17.