Impact
The vulnerability resides in the Kubernetes Operator component of Oracle TimesTen In‑Memory Database. An attacker with low‑privileged access over HTTPS can trigger a hang or repetitive crash of the database, effectively rendering the service unavailable. The flaw, identified as CWE‑400 (Resource Exhaustion), does not compromise data confidentiality or integrity but disrupts availability through a denial‑of‑service condition.
Affected Systems
Oracle Corporation’s TimesTen In‑Memory Database, version 26.1.1.1.0, is affected. The vulnerability is tied to the operator module that runs inside a Kubernetes cluster and accepts network traffic over HTTPS.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a medium severity with a pure availability impact (AV:N, AC:L, PR:L, UI:N, S:U, C:N, I:N, A:H). EPSS of <1% suggests a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. An attacker needs network access to the operator’s HTTPS endpoint and low‑privileged credentials within the Kubernetes environment to send a crafted request that triggers the crash, resulting in a denial of service.
OpenCVE Enrichment