CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.
http://www.securityfocus.com/bid/73957
http://www.securityfocus.com/archive/1/535205/100/0/threaded
http://packetstormsecurity.com/files/131330/Security-Notice-For-CA-Spectrum.html