A vulnerability was found in Oracle Interactive Session Recorder 6.0/6.1/6.2. It has been rated as very critical. Impacted is an unknown function of the component Apache Log4j. The manipulation leads to deserialization. This vulnerability is traded as CVE-2017-5645. It is possible to initiate the attack remotely. There is no exploit available.... Weiterlesen: CVE-2017-5645 | Oracle Interactive Session Recorder 6.0/6.1/6.2 Apach…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2017-5645 | Oracle Interactive Session Recorder 6.0/6.1/6.2 Apache Log4j deserialization (Nessus ID 103526 / ID 87333)
A vulnerability was found in Oracle Interactive Session Recorder 6.0/6.1/6.2. It has been rated as very critical. Impacted is an unknown function of the…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
NVD Primärbewertung & CISA SSVCCVE-2017-5645
NVD: ModifiedNVD 9.8 · CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD-Datenstand: 08.10.2026, 22:16 UTC
Ausnutzung beobachtet: Nein Automatisierbar: Ja Technischer Impact: Total
BSI-Warnung (Deutschland)CVE-2017-5645
Oracle Fusion Middleware: Mehrere Schwachstellen14.07.2020Oracle Communications Applications: Mehrere Schwachstellen16.04.2019Oracle Virtualization: Mehrere Schwachstellen16.01.2018CISA-SSVC-Triage (vulnrichment)CVE-2017-5645
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2026-10-08T21:12:24.738394Z · CISA Coordinator
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Web Referencewww.securityfocus.com
-
Web Referencewww.securitytracker.com
-
Red Hat Security Bulletin Verifiziertredhat.com
Intelligence Digest — kostenlos Täglich die wichtigsten Security-News · jederzeit abbestellbar