An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution. | |
| Title | Insecure Deserialization via MITM in Layer 7 Policy Manager | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2026-06-10T06:39:26.498Z
Reserved: 2026-06-09T16:10:09.362Z
Link: CVE-2026-11815
No data.
Status : Received
Published: 2026-06-10T07:16:24.713
Modified: 2026-06-10T07:16:24.713
Link: CVE-2026-11815
No data.
OpenCVE Enrichment
Updated: 2026-06-10T07:30:25Z