Product
CVE-2025-48734 enables attackers to enumerate the Java classpath and ClassLoader via property injection, facilitating RCE when chained with unsafe deserialization endpoints.