S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

Java RMI Registry Class Loading Vulnerability Scanner

Tests whether Java rmiregistry allows class loading.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
6.4k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
Detail

This module takes advantage of the default configuration of the RMI Registry and RMI Activation services, which allow loading classes from any remote (HTTP) URL. As it invokes a method in the RMI Distributed Garbage Collector which is available via every RMI endpoint, it can be used against both rmiregistry and rmid, and against most other (custom) RMI endpoints as well.

Solution Advice

Change the default configuration of RMI Registry and RMI Activation services.

See the following links for specific information:

  • https://github.com/rapid7/metasploit-framework/pull/4203
  • https://github.com/rapid7/metasploit-framework/issues/6445

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.