SEAT Queue Ticket Kiosk Java RMI Registry Deserialization Vulnerability

Vulnerability

A deserialization vulnerability has been identified in SEAT Queue Ticket Kiosk versions prior to 20250827. This issue arises in the Java RMI Registry Handler component, where untrusted data is deserialized without proper validation, allowing for potential manipulation. The vulnerability can be exploited over the local network, but requires high complexity, making it difficult to exploit.

Impact

Exploitation of this vulnerability allows for unauthorized deserialization of data, which could lead to remote code execution or other malicious actions, depending on the application's handling of the deserialized objects.

Reproduction

The vulnerability can be reproduced by accessing the Java RMI Registry over the local network. Tools like Remote Method Guesser can be used to enumerate the registry, revealing bound object names and their interface types. This information can be used to understand the application architecture and potentially exploit further.

Remediation

It is recommended to apply restrictive firewall rules to block unauthorized access to the Java RMI Registry.

Added: Sep 11, 2025, 2:22 PM
Updated: Sep 11, 2025, 5:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.2
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.