Divisa Proxia Suite 9 <9.12.16,9.11.19,9.10.26,9.9.8,9.8.43and9.7.10,10.0<10.0.32,and10.1<10.1.5,SparkSpace1.0<1.0.30,1.1<1.1.2,and1.2<1.2.4,andProxiaPHR1.0<1.0.30and1.1<1.1.2allowsremotecodeexecutionviauntrustedJavadeserialization.Theproxia-errorcookieisinsecurelydeserializedineveryrequest(GETorPOST).Thus,anunauthenticatedattackercaneasilycraftaseria1.0lizedpayloadinordertoexecutearbitrarycodeviatheprepareErrorfunctioninthecom.divisait.dv2ee.controller.MVCControllerServletclassofthedv2eemvc.jarcomponent.allowsremotecodeexecutionviauntrustedJavadeserialization.Theproxia-errorcookieisinsecurelydeserializedineveryrequest(GETorPOST).Thus,anunauthenticatedattackercaneasilycraftaserializedpayloadinordertoexecutearbitrarycodeviatheprepareErrorfunctioninthecom.divisait.dv2ee.controller.MVCControllerServletclassofthedv2eemvc.jarcomponent.AffectedproductsincludeProxiaPremiumEdition2017andSparkspace.