Vulnerabilities > Apache > Flex Blazeds
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-12-28 | CVE-2017-5641 | Deserialization of Untrusted Data vulnerability in multiple products Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. | 9.8 |