Why should I never ever ever use Java serialization?
I've heard that I should never use Java serialization (Serializable/ObjectInputStream/ObjectOutputStream) because of security. What's the problem?

I've heard that I should never use Java serialization (Serializable
/ObjectInputStream
/ObjectOutputStream
) because of security. What's the problem?