Check this out: http://sunsolve.sun.com/search/document.do?assetkey=1-26-102171-1 "Seven (7) vulnerabilities with the use of "reflection" APIs in the Java Runtime Environment may independently allow an untrusted applet to elevate its privileges. For example...