Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. It allows an attacker who has low‑privileged access and can reach the Operator’s HTTPS endpoint to repeatedly cause the database to hang or crash. The impact is a loss of availability; confidentiality and integrity are not affected. This weakness corresponds to CWE-400, representing insufficient input validation or resource usage control that can be exploited for a denial‑of‑service attack.

Affected Systems

Oracle Corporation’s TimesTen In-Memory Database version 26.1.1.1.0 on Kubernetes is affected. No other vendors, products, or versions are listed.

Risk and Exploitability

The CVSS score of 6.5 highlights a moderate severity availability issue. The EPSS score of <1% indicates a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack requires network access to the Operator’s HTTPS interface; the description specifies that a low‑privileged attacker can trigger the crash, so local privilege escalation is not required. Based on the description, the most likely attack vector is HTTPS network communication with the Operator component.

Generated by OpenCVE AI on August 4, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the official patch released in the July 2026 Oracle CPU or upgrade to a version where the Kubernetes Operator bug is fixed
  • Restrict network access to the Operator’s HTTPS endpoint using firewall rules, Kubernetes NetworkPolicies, or namespace isolation so that only trusted cluster nodes can reach it
  • If HTTPS access to the Operator is not required for your deployment, disable that endpoint or limit it to completely trusted users
  • Implement monitoring to detect unexpected crashes or hangs in the TimesTen In-Memory Database and respond promptly

Generated by OpenCVE AI on August 4, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Oracle TimesTen In-Memory Database Operator

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Oracle TimesTen In-Memory Database Operator

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title TimesTen In-Memory Database Kubernetes Operator Vulnerability Enables Denial of Service via HTTPS

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title TimesTen In-Memory Database Kubernetes Operator Vulnerability Enables Denial of Service via HTTPS

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:18:19.367Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60403

cve-icon Vulnrichment

Updated: 2026-07-24T16:18:14.583Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption