### [CVE-2015-2828](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2828) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data. ### POC #### Reference - http://packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.html #### Github - https://github.com/PalindromeLabs/Java-Deserialization-CVEs