Fishbowl.Inventory.Server.decodeObject.Insecure.Deserialization
Description
This indicates an attack attempt to exploit an Insecure Deserialization Vulnerability in Fishbowl Inventory Fishbowl Server.
This vulnerability is due to improper input validation before deserialization. A remote, unauthenticated attacker could exploit this vulnerability by sending a crafted request to the target server. Successfully exploiting this vulnerability could result in remote code execution.
Affected Products
Fishbowl Inventory Fishbowl Server prior to 2022.4.1
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://help.fishbowlinventory.com/s/article/Release-Notes
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2024-07-04 | 28.821 | Sig Added |
2023-02-28 | 22.503 | Default_action:pass:drop |
2023-02-21 | 22.499 |