A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://www.fishbowlinventory.com | product |
https://www.whiteoaksecurity.com/blog/fishbowl-disclosure-cve-2022-29805/ | third party advisory exploit technical description |