Tag: Java deserialization
You are here: Home \ Java deserialization
Adobe released an important security hotfix for several versions of Coldfusion, resolving two bugs, Tuesday morning.
A Java serialization vulnerability disclosed more than a year ago figured to have a long shelf life. It lived in popular Java application development frameworks such as Apache Commons Collections—where it’s been patched—and not to mention widely deployed application servers such as Oracle WebLogic, IBM WebSphere, Red Hat’s JBoss and others. PayPal this week put...