High severity7.5NVD Advisory· Published Jul 7, 2022· Updated Jun 17, 2026
CVE-2015-5236
CVE-2015-5236
Description
It was discovered that the IcedTea-Web used codebase attribute of the tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- IcedTea-Web/IcedTea-Webdescription
Patches
Vulnerability mechanics
References
1- bugzilla.redhat.com/show_bug.cginvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.