Java object deserialization of user-supplied data

Description

It was determined that your web application is performing Java object deserialization of user-supplied data. Arbitrary object deserialization is inherently unsafe, and should never be performed on untrusted data. Consult Web references section for more information about this issue.

Remediation

Java object deserialization should not be performed on user-supplied data.

References
Severity
Classification
Tags
  • Abuse Of Functionality