CVE-2016-6802

HIGH7.5EPSS 13.5%

Improper Access Control in Apache Shiro

Published: 5/14/2022Modified: 4/28/2026

Description

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (5)