Impact
A low‑privileged attacker who has logged onto the infrastructure that hosts Oracle TimesTen In‑Memory Database can compromise the database instance through a flaw in the Kubernetes Operator. This vulnerability allows the attacker to read select data stored in the database, thereby compromising confidentiality. The weakness is a case of information exposure identified by CWE‑200.
Affected Systems
The vulnerability affects Oracle TimesTen In‑Memory Database version 26.1.1.1.0, reachable via the Kubernetes Operator on the host infrastructure. Only deployments using this exact release are susceptible to the described data‑reading issue.
Risk and Exploitability
The CVSS base score of 3.8 reflects a low‑severity confidentiality impact with local access and low privilege, and the EPSS score of less than 1% indicates a low probability of exploitation. However, because the attack requires only local access, any adversary who has already gained a foothold on the underlying system can exploit the flaw to read sensitive data. The vulnerability is not listed in CISA KEV, and the scope change may affect other products, but the overall risk remains limited to compromised local hosts.
OpenCVE Enrichment