Amazon interview question

What potentially issue exist with Java deserialization, why can it be exploited and how can it be mitigated?