upgrade jboss-marshalling to 1.3.18 GA or later to resolve the linked bugs
Fields are not cloned before calling readObject in SerializableCloner https://bugzilla.redhat.com/show_bug.cgi?id=967079
QA_ACK granted, JBoss Marshalling 1.3.17.GA and 1.3.18.GA contains bug fixes only. EAP 6.1.0 GA contains 1.3.16.GA https://issues.jboss.org/browse/JBMAR/fixforversion/12320281 https://issues.jboss.org/browse/JBMAR/fixforversion/12320971
Version of jboss-marshalling was upgraded to 1.3.18.GA-redhat-1 in EAP 6.1.1 ER3