Domanda di colloquio di Amazon

What potentially issue exist with Java deserialization, why can it be exploited and how can it be mitigated?