Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2016-4437

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-284

Beschrijving

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

Required action: Apply updates per vendor instructions.

Vendors

Apache

Affected products

Shiro

References