CVE Database
/

CVE-2015-5236

Back to search

CVE-2015-5236

Published: Jul 7, 2022

Modified: Aug 6, 2024

PUBLISHED

Description

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

VendorProductVersions

n/a

Icedtea-web

affected
Unkown

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now