Java RMI based services were one of the major victims of the “Java Deserialization Apocalypse” in 2015. Oracle mitigated the problem by introducing multiple filters, however, under certain conditions, a attacker might still be able to exploit these services and gain RCE on the target.