Impact
The TimesTen In‑Memory Database Kubernetes Operator contains a privilege escalation weakness (CWE‑269) that allows a logged‑on, high‑privileged user on the host to take full control of the database system. This local win elevates the attacker’s authority to compromise Confidentiality, Integrity, and Availability of the data stored in the database.
Affected Systems
All Oracle TimesTen In‑Memory Database installations running version 26.1.1.1.0 that are deployed with the Kubernetes Operator in any supported environment.
Risk and Exploitability
The CVSS 3.1 base score of 6.7 indicates a moderate severity. The EPSS score of less than 1% shows that exploitation attempts are currently sparse, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker with local high‑privilege access to the host where TimesTen runs; no network connectivity or user interaction is needed. The attack surface is therefore limited to compromised or otherwise accessible pods or hosts that can run the Operator.
OpenCVE Enrichment