Critical severity9.8NVD Advisory· Published Dec 29, 2017· Updated May 13, 2026
CVE-2014-9515
CVE-2014-9515
Description
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/DozerMapper/dozer/issues/217nvdIssue TrackingThird Party Advisory
- github.com/pentestingforfunandprofit/research/tree/master/dozer-rcenvdIssue TrackingThird Party Advisory
- infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdfnvdIssue TrackingThird Party Advisory
- www.securityfocus.com/bid/107970nvd
- github.com/DozerMapper/dozer/issues/410nvd
- github.com/DozerMapper/dozer/issues/786nvd
- github.com/DozerMapper/dozer/pull/447/commits/ccd550696f3df8545319ffa9c6adafc8eca2334cnvd
- security.netapp.com/advisory/ntap-20240719-0002/nvd
- www.oracle.com/security-alerts/cpuApr2021.htmlnvd
News mentions
0No linked articles in our index yet.