Impact
A low‑privileged attacker who can reach the TimesTen In‑Memory Database Operator over HTTPS can gain unauthorized read access to a subset of the database. The vulnerability, identified as CWE‑200 Information Exposure, allows a remote data disclosure in which sensitive information may be exposed to an attacker who is not authorized to read it, but does not affect integrity or availability.
Affected Systems
The affected product is Oracle TimesTen In‑Memory Database version 26.1.1.1.0. This version is managed via the Kubernetes Operator component. No other vendors or versions are listed as affected.
Risk and Exploitability
The CVSS v3.1 Base Score is 4.3, indicating a low‑to‑moderate severity with a Confidentiality impact. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTPS, requiring only low‑privileged network access and no elevated privileges on the host or database. Consequently, the overall risk is low to moderate but should be mitigated by applying the official patch or restricting network exposure.
OpenCVE Enrichment