---
title: "40 more software libraries hit by Java deserialistion bug"
url: "https://thecybersecurityplace.com/40-more-software-libraries-hit-by-java-deserialistion-bug/"
date: "2015-12-07T08:43:58+00:00"
section: "Software"
tags:
  - "Software Security"
source: "cbronline.com"
source_url: "http://www.cbronline.com/news/cybersecurity/data/40-more-software-libraries-hit-by-java-deserialistion-bug-4746191"
---

# 40 more software libraries hit by Java deserialistion bug

December 7, 2015 · Reported by cbronline.com

> 40 more software libraries may be affected by a Java deserialisation vulnerability than was originally thought, folllowing initial research by Foxglove Security.
>
> The risk comes from apps not validating untrusted input before deserialisation, with this affecting all apps that accept serialised Java objects.
>
> Various popular open source libraries are involved, including hadoop-mapreduce-client-core, Apache Directory API All, and Standalone Jar.

[Read the full article at cbronline.com](http://www.cbronline.com/news/cybersecurity/data/40-more-software-libraries-hit-by-java-deserialistion-bug-4746191)

**Tags:** [Software Security](https://thecybersecurityplace.com/tag/software-security/)
