This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. The existance of the flaw within the JavaSerializationCodec and ParameterVersionJavaSerializationCodec class, due to the lack of proper validation of user-supplied data, can result in deserialization of untrusted data. |