CVE-2015-5236
Last modified
CVE-2015-5236 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.. EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icedtea-Web Project | Icedtea-Web | All versions |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1256403Exploit, Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1256403Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5236?
How severe is CVE-2015-5236?
How do I fix CVE-2015-5236?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5230The DNS packet parsing/generation code in PowerDNS (aka pdns…7.5
- CVE-2015-5231The service daemon in CRIU does not properly restrict access…
- CVE-2015-5232Race conditions in opa-fm before 10.4.0.0.196 and opa-ff bef…8.1
- CVE-2015-5233Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly …
- CVE-2015-5234IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not pro…
- CVE-2015-5235IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not pro…
- CVE-2015-5237protobuf allows remote authenticated attackers to cause a he…8.8
- CVE-2015-5238Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-5239Integer overflow in the VNC display driver in QEMU before 2.…6.5
- CVE-2015-5240Race condition in OpenStack Neutron before 2014.2.4 and 2015…
- CVE-2015-5241After logging into the portal, the logout jsp page redirects…
- CVE-2015-5242OpenStack Swift-on-File (aka Swiftonfile) does not properly …
Are you affected by CVE-2015-5236?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
