While waiting for their website to accept my upload I was poking around and decided to see what I could get into. I found that the addresses were something like /user/<sequential id> so I wondered "could I look at another user's page by changing the ID? Na, no way that would work"...but it did work. In fact I was able to see and theoretically control app submissions for all 500 developers at the time. This set of pages even included tax IDs.
So I immediately went to Palm and told them about the issue and how to reproduce. After about two weeks they finally reported that the issue was fixed...except it wasn't. What they did was change the way the pages were accessed from a standard GET with the ID in the URL to using JavaScript to accomplish the same thing but kinda sorta hide the ID (so basically fetch content via JavaScript versus page loading via direct browsing). So naturally I was able to change the ID and still get in.
It would take them another month to finally fix this issue. I was never able to convince them to let developers know their tax IDs may have been exposed along with all of their other information. I did get a special mention in one of their release notes but they spelled my name wrong :(