CPE
Apache Roller 6.1.5 is susceptible to unauthenticated remote code execution via insecure Java deserialization on the XML-RPC endpoint, which is triggered by an attacker-supplied 'ex:serializable' extension type before authentication is processed.