An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom api Gateway |
|
| Vendors & Products |
Broadcom
Broadcom api Gateway |
Wed, 10 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution. | |
| Title | Insecure Deserialization via MITM in Layer 7 Policy Manager | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: symantec
Published:
Updated: 2026-06-10T06:39:26.498Z
Reserved: 2026-06-09T16:10:09.362Z
Link: CVE-2026-11815
No data.
Status : Received
Published: 2026-06-10T07:16:24.713
Modified: 2026-06-10T07:16:24.713
Link: CVE-2026-11815
No data.
OpenCVE Enrichment
Updated: 2026-06-10T10:45:04Z
Weaknesses