#VU51012 Deserialization of Untrusted Data in Apache Tomcat - CVE-2021-25329
Published: March 1, 2021
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Note, the vulnerability exists due to incomplete fix for #VU28158 and requires a certain specific configuration.