7.5
CVSSv3

CVE-2015-5236

Published: 07/07/2022 Updated: 15/07/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

It exists that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

icedtea-web project icedtea-web -

Vendor Advisories

A flaw was discovered that IcedTea-Web did not properly determine an applet's origin when performing same-origin checks A malicious page could use this flaw to bypass the Same Origin Policy (SOP) and access data on unrelated sites using a spoofed value for the applet's codebase attribute ...