Impact
A low privileged attacker who is able to log into the infrastructure where the TimesTen In‑Memory Database runs can use a difficult‑to‑exploit flaw in the Kubernetes Operator component to compromise the database. Successful exploitation lets the attacker read or modify data stored in TimesTen, without affecting the integrity or availability of the service it permits unauthorized access to critical data. The vulnerability is a CWE‑284 (Access Control Failure).
Affected Systems
Oracle TimesTen In-Memory Database, version 26.1.1.1.0. The flaw applies only to this specific release and to the Kubernetes Operator that manages it.
Risk and Exploitability
The CVSS v3.1 score is 5.6, indicating moderate risk with a local attacker who has low privileges and no user interaction required. The EPSS score of < 1% suggests that exploitation is unlikely but not impossible, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to log on to the host environment and exploit the Operator component; the success of the attack can lead to unauthorized data access across all TimesTen instances in scope.
OpenCVE Enrichment