Impact
The vulnerability is located in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. It allows an attacker who has low‑privileged access and can reach the Operator’s HTTPS endpoint to repeatedly cause the database to hang or crash. The impact is a loss of availability; confidentiality and integrity are not affected. This weakness corresponds to CWE-400, representing insufficient input validation or resource usage control that can be exploited for a denial‑of‑service attack.
Affected Systems
Oracle Corporation’s TimesTen In-Memory Database version 26.1.1.1.0 on Kubernetes is affected. No other vendors, products, or versions are listed.
Risk and Exploitability
The CVSS score of 6.5 highlights a moderate severity availability issue. The EPSS score of <1% indicates a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack requires network access to the Operator’s HTTPS interface; the description specifies that a low‑privileged attacker can trigger the crash, so local privilege escalation is not required. Based on the description, the most likely attack vector is HTTPS network communication with the Operator component.
OpenCVE Enrichment