Loading
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Use CWE-321, Apache vendor hub and Aurora product page to widen CVE-2016-4437 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-27905 for nearby disclosures in the same product family.