CVE-2016-4437 | Apache Shiro up to 1.2.4 Cipher Key access control (ID 137310 / EDB-48410)
A vulnerability classified as critical has been found in Apache Shiro up to 1.2.4. Affected is an unknown function of the component Cipher Key Handler. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2016-4437. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.