S4E just found a high top 10 tcp port service scan
medium·Product Based Network Vulnerabilities·Updated Dec 16, 2023

Java RMI Protocol Detection Scanner

Misconfigured RMI Registry and RMI Activation Services allowing the loading of classes from a remote URL.

Est. Time~7 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2
Times Used
by S4E users
2
Assets Scanned
domains & IPs
2
Vulnerabilities Found
confirmed findings
References
Detail

What is Java RMI?

Java RMI server is a virtual entity exposed over the network that allows other remote parties (clients) to execute methods on a system (technically a JVM running on that system) on which it is running. It’s nothing exceptional in the programming world — where similar concepts like Remote Procedure Call (RPC) are widely used.


Thus, by running an exposed RMI Server on a system, one can allow external actors to interact with it and possibly execute methods on the RMI Server. These methods should be defined within the Server implementation. Once they are called by a client, they will be executed on the Server and the return values will be returned to the client.

Solution Advice

Access restriction should be applied.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.