CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.
packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.html
www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20150407-01-security-notice-for-ca-spectrum.aspx
www.securityfocus.com/archive/1/535205/100/0/threaded
www.securityfocus.com/bid/73957