Java RMI Registry Class Loading Vulnerability Scanner

Tests whether Java rmiregistry allows class loading.

Short Info


Level

Medium

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

15 seconds

Time Interval

2 months 4 weeks

Scan only one

Domain, IPv4, Subdomain

Toolbox

-

This module takes advantage of the default configuration of the RMI Registry and RMI Activation services, which allow loading classes from any remote (HTTP) URL. As it invokes a method in the RMI Distributed Garbage Collector which is available via every RMI endpoint, it can be used against both rmiregistry and rmid, and against most other (custom) RMI endpoints as well.

Get started to protecting your Free Full Security Scan