Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who can reach the TimesTen In‑Memory Database Operator over HTTPS can gain unauthorized read access to a subset of the database. The vulnerability, identified as CWE‑200 Information Exposure, allows a remote data disclosure in which sensitive information may be exposed to an attacker who is not authorized to read it, but does not affect integrity or availability.

Affected Systems

The affected product is Oracle TimesTen In‑Memory Database version 26.1.1.1.0. This version is managed via the Kubernetes Operator component. No other vendors or versions are listed as affected.

Risk and Exploitability

The CVSS v3.1 Base Score is 4.3, indicating a low‑to‑moderate severity with a Confidentiality impact. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTPS, requiring only low‑privileged network access and no elevated privileges on the host or database. Consequently, the overall risk is low to moderate but should be mitigated by applying the official patch or restricting network exposure.

Generated by OpenCVE AI on August 2, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's July 2026 security patch to TimesTen In‑Memory Database 26.1.1.1.0.
  • Restrict HTTPS access to the Kubernetes Operator by configuring firewall or network policies to allow only trusted internal networks or authenticated clients.
  • If the patch cannot be applied immediately, temporarily disable external HTTPS traffic to the Operator or implement an access control mechanism to prevent unauthenticated requests until the patch is installed.

Generated by OpenCVE AI on August 2, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title TimesTen In‑Memory Database Operator Information Disclosure via HTTPS

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title HTTP-based Kubernetes Operator Data Exposure in Oracle TimesTen

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title HTTP-based Kubernetes Operator Data Exposure in Oracle TimesTen

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:13:35.400Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60408

cve-icon Vulnrichment

Updated: 2026-07-24T16:13:26.926Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor