Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/5784
http://archives.neohapsis.com/archives/bugtraq/2000-12/0241.html