Skip to main content
brianl6882383
Participant
January 15, 2016
Question

Java Deserialization - Risk Assessment Assistance

  • January 15, 2016
  • 1 reply
  • 403 views

Good afternoon,

We have been notified by our internal IT staff that there is a potential risk for programs developed with Java code, where they deserialize untrusted data without verifying the results first.  Can you verify with your development teams to see if they are aware of the unsafe deserialization vulnerabilities that can lead to anonymous remote arbitrary code execution?  Our understanding is that these risks involve both applications and infrastructure, and both need to be assessed, which is what we are hoping you can assist with. 

Additional background about the vulnerability is available at the following web link:  http://cwe.mitre.org/data/definitions/502.html

Due to the nature of this particular risk our company is very concerned and need your immediate assistance in determining whether this application is impacted.  If you can provide an update by the end of next week it would be greatly appreciated.

This topic is closed to new replies. Start a new post to keep the conversation going.

1 reply

alisterblack
Inspiring
January 18, 2016

Hi,

You can find our security blog here http://blogs.adobe.com/psirt/

As well as details of security updates for our applications it also has a contact address for the team.

They should be able to assist further.