Impact
The flaw is in the Kubernetes Operator of Oracle TimesTen In‑Memory Database. A high‑privileged local attacker who can log on to the infrastructure where the database runs may gain unauthorized access to the database. The attacker can then create, update, delete, or read data, and can cause a partial denial of service.
Affected Systems
Oracle TimesTen In‑Memory Database version 26.1.1.1.0 is impacted. No other products are explicitly listed as affected, but an attack on this component could potentially alter the state of additional products that rely on the database.
Risk and Exploitability
The CVSS base score of 5.7 indicates moderate severity, while the EPSS score of < 1 % signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog and requires a local attacker with high privileges and no user interaction. Because the attack scope changes, the attacker can gain partial control over the database, allowing unauthorized modifications, reads, and limited denial of service.
OpenCVE Enrichment