Java Web Start has a vulnerability in the way it handles Java system properties defined in JNLP files. Java Web Start in J2SE 1.4.2 releases prior 1.4.2_07 are vulnerable.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/36709/javaWebStart.txt
Source: https://packetstormsecurity.com/files/36709/javaWebStart.txt.html