CVE-2016-4437
Apache Shiro Code Execution Vulnerability
- Published
- Jun 7, 2016
- Updated
- Oct 21, 2025
- Assigning CNA
- redhat
- Evidence observed
- May 1, 2020
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
Sources
8这是基于cve-2016-4437简单的漏洞复现代码
- shisoserialExploit
一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
- CVE-2016-4437Exploit
1.验证CVE-2016-4437、2.解析rememberMe的文件和CBC加密的IV偏移
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.