The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.