dozer: Potential remote code execution (RCE) via dozer's reflection-based type conversion
Published Dec 29, 2017
9.8
CRITICALCVSS 3.1
EPSS 5.64%
Description
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.
Affected products
No data.
- ≤ 5.5.1
-
- Version 0StatusaffectedConstraints<=5.5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dozer Project | Dozer | n/a |
|
Red Hat JBoss Fuse 6
dozer
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Fuse 6 | dozer | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jul 23, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 5.64% (0.05645) | 92.72th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.60% (0.05599) | 91.89th | v5 (v2026.06.15) |
| Mar 16, 2026 | 5.36% (0.05361) | 89.96th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.55% (0.02548) | 84.13th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.22% (0.06225) | 84.38th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.56% (0.02556) | 84.47th | v4 (v2025.03.14) |
| Dec 12, 2024 | 4.91% (0.04908) | 93.09th | v3 (v2023.03.01) |
| Dec 9, 2023 | 4.91% (0.04908) | 91.94th | v3 (v2023.03.01) |
| Nov 8, 2023 | 4.75% (0.04745) | 91.77th | v3 (v2023.03.01) |
| Jun 12, 2023 | 4.47% (0.04471) | 91.23th | v3 (v2023.03.01) |
| May 22, 2023 | 5.82% (0.05823) | 92.23th | v3 (v2023.03.01) |
| May 8, 2023 | 5.62% (0.05624) | 92.06th | v3 (v2023.03.01) |
| Apr 9, 2023 | 6.62% (0.06618) | 92.69th | v3 (v2023.03.01) |
| Mar 7, 2023 | 9.07% (0.09074) | 93.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07343) | 92.53th | v2 (v2022.01.01) |
| Sep 25, 2022 | 7.34% (0.07343) | 92.23th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.15% (0.07154) | 91.53th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.15% (0.07154) | 80.03th | v2 (v2022.01.01) |
References (13)
- http://www.securityfocus.com/bid/107970 vdb-entry
- https://access.redhat.com/security/cve/CVE-2014-9515 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1530804 Issue Tracking
- https://github.com/DozerMapper/dozer/issues/217 Issue TrackingThird Party Advisory
- https://github.com/DozerMapper/dozer/issues/410
- https://github.com/DozerMapper/dozer/issues/786
- https://github.com/DozerMapper/dozer/pull/447/commits/ccd550696f3df8545319ffa9c6adafc8eca2334c
- https://github.com/pentestingforfunandprofit/research/tree/master/dozer-rce Issue TrackingThird Party Advisory
- https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf Issue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-9515
- https://security.netapp.com/advisory/ntap-20240719-0002/
- https://www.cve.org/CVERecord?id=CVE-2014-9515
- https://www.oracle.com/security-alerts/cpuApr2021.html
Change history (0)
No recorded changes yet.