Description
With a little work, I think that an application could dig up the LogFactory and cast it to LogToFile. This could give the application elevated privileges to overwrite sensitive Derby-managed data.
Attachments
Attachments
Issue Links
- relates to
-
DERBY-6648 Application code should not be able to call ContextService.getContextOrNull()
- Closed