In <[email protected]>, on 03/31/2012
   at 09:57 PM, Clark Morris <[email protected]> said:

>Java on the server side is effectively executable code.

Yes, Java, Javascript and PDF are code, but a web browser does not
give code to a web server. OTOH, a web server can give code to a web
browser, and a browser running under z/OS would have the same
vulnerabilities as a browser on any other platform. 

>If dynamic SQL is allowed,

Is there a way to force it to a sandbox?
 
-- 
     Shmuel (Seymour J.) Metz, SysProg and JOAT
     ISO position; see <http://patriot.net/~shmuel/resume/brief.html> 
We don't care. We don't have to care, we're Congress.
(S877: The Shut up and Eat Your spam act of 2003)

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to