Some classes which extend Serializable may be serialized and deserialized, compromising security. Some example of these classes are BAuthorization and GmsEntity (and all other extending from it such as EUser).
Some investigation should be done to remove this capability if possible.