보안뉴스 아카이브
긴급도 75/100 심각도 미평가 · 미평가 악용확률 99.8% CISA KEV · 2021-11-03

CVE-2016-4437

CISA 기관 조치 기한: 2022-05-03

Apache Shiro

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC

NVD 상세 ↗   참고 링크 ↗

← 취약점 목록