Connection caches and security

Your application may have a potential security hole if Java component implementation classes are deployed under EAServer’s html directory. An unauthorized user can implement a program that connects to EAServer’s HTTP port and downloads the component’s implementation classes. The user can then decompile the classes and gain access to potentially sensitive information such as database passwords. To close this security hole, Sybase recommends one of the following approaches: