RULE(RULE ID:716913)

Rule General Information
Release Date: 2024-04-29
Rule Name: Suspicious Java Deserialization Detection - RMI
Severity:
CVE ID:
Rule Protection Details
Description: com.sun.jndi.rmi.registry is a package in Java belonging to the Java Naming and Directory Interface (JNDI) designed to work with the Java Remote Method Invocation (RMI) registry. This package provides classes and interfaces that enable applications to interact with the RMI registry using JNDI. This class can be deserialized and is often used by malicious attackers to perform java deserialization attacks. This rule is used to detect suspicious java deserialization class registry in traffic.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.