EAP 7.4 unable to deserialized classes after applying patch 13
Issue
- Since the update 13 for the JBoss 7.4 we encounter following error message:
"java.io.InvalidClassException: Filtering rejected org.jboss.marshalling.AbstractUnmarshaller$FilterInputImpl@xxxxxx: unmarshallClass=<class java.sql.Date> arrayLength=<-1> depth=<17> references=<300001> streamBytes=<1411635>"
This error happens during deserialization. Do you know if there is a connection between the fix 'CVE-2023-3171 eap-7: heap exhaustion via deserialization' from the update 13 and our error ? Do you have a solution for that problem?
Environment
- Red Hat JBoss Enterprise Application Platform (EAP)
- 7.4.13+
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.