IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade icedtea-web | Jul 30, 2024 | Oct 9, 2015 |
| Oracle_linux | — | Upgrade icedtea-web-javadocUpgrade icedtea-web | May 12, 2016 | Oct 9, 2015 |
| Suse | — | Upgrade icedtea-webUpgrade java-1_7_0-openjdk-pluginUpgrade java-1_8_0-openjdk-pluginUpgrade icedtea-web-javadoc | Dec 18, 2015 | Oct 5, 2015 |
| Ubuntu | — | Upgrade icedtea-6-pluginUpgrade icedtea-7-plugin | Nov 30, 2015 | Oct 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub