CVE-2017-3201: Exadel Flamingo Amf-Serializer
High severity, CVSS 8.1. EPSS: 5.4% chance of exploitation in the next 30 days.
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.
Affected products
- Exadel Flamingo Amf-Serializer: version 2.2.0 only
Published 2018-06-11. Last modified 2026-06-17.