Skip to main content

         This documentation site is for previous versions. Visit our new documentation site for current releases.      

Protect against insecure deserialization (8.2)

Updated on May 3, 2021

Deserialization is the process of rebuilding a data stream into a Java object. The Open Web Application Security Project (OWASP) has identified insecure deserialization as one of the top 10 security vulnerabilities for web applications. Pega Platform™ protects against this vulnerability by providing filters that prevent deserialization of suspect data streams. You can configure these filters from the Deserialization Blacklist landing page, as shown in the following figure.


Deserialization Blacklist landing page

For more information, see Configuring the deserialization filter.

  • Previous topic Create single sign-on authentication services from App Studio (8.2)
  • Next topic Configure platform authentication with the basic credentials authentication service type (8.2)

Have a question? Get answers now.

Visit the Support Center to ask questions, engage in discussions, share ideas, and help others.

Did you find this content helpful?

Want to help us improve this content?

We'd prefer it if you saw us at our best. is not optimized for Internet Explorer. For the optimal experience, please use:

Close Deprecation Notice
Contact us