Impact
A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, allowing a locally privileged attacker with infrastructure logon to abuse improper access control and privilege management. The flaw permits the attacker to read any data stored in the database, effectively bypassing normal authorization checks and potentially gaining full visibility of all TimesTen data. The CVSS v3.1 Base Score of 6.5 highlights a moderate severity with a focus on confidentiality impact.
Affected Systems
Oracle TimesTen In-Memory Database version 26.1.1.1.0 is affected. Systems running this exact release, specifically the Kubernetes Operator that manages database instances, are vulnerable. No other product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, combining a local attack vector (AV:L), low attack complexity (AC:L), low privileges required (PR:L), and no user interaction (UI:N). The EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation yet. However, because the flaw changes scope (S:C) and can expose all critical data, it poses a significant risk to systems where the affected release is deployed.
OpenCVE Enrichment