An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom api Gateway |
|
| Vendors & Products |
Broadcom
Broadcom api Gateway |
Wed, 10 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution. | |
| Title | Insecure Deserialization via MITM in Layer 7 Policy Manager | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: symantec
Published: 2026-06-10T06:39:26.498Z
Updated: 2026-06-10T14:42:44.513Z
Reserved: 2026-06-09T16:10:09.362Z
Link: CVE-2026-11815
Updated: 2026-06-10T14:42:37.733Z
Status : Awaiting Analysis
Published: 2026-06-10T07:16:24.713
Modified: 2026-06-10T20:13:47.847
Link: CVE-2026-11815
No data.