#VU67206 Improper access control in Apache Shiro - CVE-2016-4437
Published: September 13, 2022 / Updated: January 2, 2024
Apache Shiro
Apache Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code or bypass intended access restrictions.
The vulnerability exists due to improper access restrictions when a cipher key is not been configured for the "remember me" feature. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.
Remediation
External links
- http://packetstormsecurity.com/files/137310/Apache-Shiro-1.2.4-Information-Disclosure.html
- http://packetstormsecurity.com/files/157497/Apache-Shiro-1.2.4-Remote-Code-Execution.html
- http://rhn.redhat.com/errata/RHSA-2016-2035.html
- http://rhn.redhat.com/errata/RHSA-2016-2036.html
- http://www.securityfocus.com/archive/1/538570/100/0/threaded
- http://www.securityfocus.com/bid/91024