CVE-2015-5236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
07/07/2022
Last modified:
15/07/2022

Description

It was discovered that the IcedTea-Web used codebase attribute of the tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:icedtea-web_project:icedtea-web:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools