Exploiting JVM deserialization vulns despite a broken class loader

A broken classloader made exploitation of a Java deserialization vulnerability more tricky, but it was still possible to exploit it to e.g. delete files on the server.

