Reader

Why should I never ever ever use Java serialization?

| Software Engineering Stack Exchange | Default

I've heard that I should never use Java serialization (Serializable/ObjectInputStream/ObjectOutputStream) because of security. What's the problem?