Impact
A low‑privileged attacker with network access via HTTPS can exploit a flaw in the Oracle TimesTen In‑Memory Database Kubernetes Operator, enabling full control of the database. The vulnerability permits the attacker to compromise confidentiality, integrity, and availability, effectively resulting in a takeover of the database as detailed in the official advisory.
Affected Systems
The affected product is Oracle TimesTen In‑Memory Database version 26.1.1.1.0. The description notes that successful attacks may also have scope changes that could impact additional products within the environment.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates critical severity, and the EPSS score of less than 1% suggests that, although the vulnerability is technically easy to exploit, its current exploitation probability is low. The issue is not listed in CISA’s KEV catalog. Attackers would need only low privilege and network access to the HTTPS endpoint of the Kubernetes Operator, which may also influence the broader environment due to the scope change noted in the vulnerability description.
OpenCVE Enrichment