Java Deserialization - Risk Assessment Assistance
Good afternoon,
We have been notified by our internal IT staff that there is a potential risk for programs developed with Java code, where they deserialize untrusted data without verifying the results first. Can you verify with your development teams to see if they are aware of the unsafe deserialization vulnerabilities that can lead to anonymous remote arbitrary code execution? Our understanding is that these risks involve both applications and infrastructure, and both need to be assessed, which is what we are hoping you can assist with.
Additional background about the vulnerability is available at the following web link: http://cwe.mitre.org/data/definitions/502.html
Due to the nature of this particular risk our company is very concerned and need your immediate assistance in determining whether this application is impacted. If you can provide an update by the end of next week it would be greatly appreciated.
