Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Kubernetes Operator component of Oracle TimesTen In‑Memory Database. An attacker with low‑privileged access over HTTPS can trigger a hang or repetitive crash of the database, effectively rendering the service unavailable. The flaw, identified as CWE‑400 (Resource Exhaustion), does not compromise data confidentiality or integrity but disrupts availability through a denial‑of‑service condition.

Affected Systems

Oracle Corporation’s TimesTen In‑Memory Database, version 26.1.1.1.0, is affected. The vulnerability is tied to the operator module that runs inside a Kubernetes cluster and accepts network traffic over HTTPS.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a medium severity with a pure availability impact (AV:N, AC:L, PR:L, UI:N, S:U, C:N, I:N, A:H). EPSS of <1% suggests a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. An attacker needs network access to the operator’s HTTPS endpoint and low‑privileged credentials within the Kubernetes environment to send a crafted request that triggers the crash, resulting in a denial of service.

Generated by OpenCVE AI on August 4, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle TimesTen to a version that includes the fix for the Kubernetes Operator vulnerability, if such an update is available.
  • Restrict HTTPS access to the TimesTen Operator by configuring Kubernetes network policies, firewall rules, or identity‑based controls to limit connections to trusted hosts or subnets.
  • Monitor TimesTen Operator logs and Kubernetes cluster events for abnormal crashes or hangs, and configure alerts to notify administrators immediately.

Generated by OpenCVE AI on August 4, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Kubernetes Operator HTTPS in Oracle TimesTen In‑Memory Database

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via HTTPS on Oracle TimesTen Kubernetes Operator

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via HTTPS on Oracle TimesTen Kubernetes Operator

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:02:19.207Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60404

cve-icon Vulnrichment

Updated: 2026-07-24T14:02:15.417Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption