RMI annotates codebase information as part of the serialized state of a remote object reference to assist RMI clients in loading the required classes and interfaces associated with the object at runtime. The RMI servers most likely to be effected are those which are invoked only by RMI clients executing on the same host as the server. RMI Registry IssueĪ bug in the rmiregistry command included in this release may cause unintended exceptions to be thrown when an RMI server attempts to bind an exported object which includes codebase annotations using the 'file:' URL scheme. Note: For more information, see the Blacklist Jar Feature section in the Java SE 6u14 Release Notes. This update release includes the following new entries to the Blacklist: Oracle used release version 6u28 for an internal build, which was not necessary once the fixes delivered on Java SE 6u29 were released.
There is no publicly available Java SE 6u28 release. Release Java SE 6u29 follows release Java SE 6u27.
For more information about security baselines, see Deploying Java Applets With Family JRE Versions in Java Plug-in for Internet Explorer.