Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who has logged onto the infrastructure that hosts Oracle TimesTen In‑Memory Database can compromise the database instance through a flaw in the Kubernetes Operator. This vulnerability allows the attacker to read select data stored in the database, thereby compromising confidentiality. The weakness is a case of information exposure identified by CWE‑200.

Affected Systems

The vulnerability affects Oracle TimesTen In‑Memory Database version 26.1.1.1.0, reachable via the Kubernetes Operator on the host infrastructure. Only deployments using this exact release are susceptible to the described data‑reading issue.

Risk and Exploitability

The CVSS base score of 3.8 reflects a low‑severity confidentiality impact with local access and low privilege, and the EPSS score of less than 1% indicates a low probability of exploitation. However, because the attack requires only local access, any adversary who has already gained a foothold on the underlying system can exploit the flaw to read sensitive data. The vulnerability is not listed in CISA KEV, and the scope change may affect other products, but the overall risk remains limited to compromised local hosts.

Generated by OpenCVE AI on August 4, 2026 at 03:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade for TimesTen version 26.1.1.1.0 immediately.
  • Restrict local access to the hosts running the database by enforcing a least‑privilege model and removing unnecessary user accounts.
  • Configure the database to grant read permissions only to explicitly required roles and audit any read operations for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 03:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Read via Local Access in Oracle TimesTen In-Memory Database

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Read via Local Access in Oracle TimesTen In-Memory Database

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Read in Oracle TimesTen In‑Memory Database
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Read in Oracle TimesTen In‑Memory Database
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:03:04.329Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60405

cve-icon Vulnrichment

Updated: 2026-07-24T14:02:59.866Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor