Vulnerabilities/

Serialized Object Found

Impact: High

Description

Object serialization allows transferring complex data structures over channels like HTTP. However, the presence of a serialized object within the application indicates potential vulnerabilities related to object deserialization. Deserialization of objects from untrusted sources can lead to various security risks, including remote code execution and data tampering.

Recommendation

To address the risk associated with serialized objects:

References

Last updated on May 13, 2024

This issue is available in SmartScanner Professional

See Pricing