Java RMI based services were one of the major victims of the “Java Deserialization Apocalypse” in 2015. Oracle mitigated the problem by introducing multiple filters, however, under certain conditions, a attacker might still be able to exploit these services and gain RCE on the target.
Hans-Martin Münch is the CEO of MOGWAI LABS GmbH, an infosec boutique with a strong emphasis on offensive security, based in Neu-Ulm. He also teaches the elective course “penetration testing” at the university of applied sciences Ulm.