Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Kubernetes Operator component of Oracle TimesTen In‑Memory Database allows a low‑privileged attacker with network access via HTTPS to induce a partial denial of service. The vulnerability stems from improper resource handling, which is inferred to be a resource‑exhaustion weakness corresponding to CWE‑400. An attacker who succeeds can cause the database to become partially unavailable, disrupting availability for users that rely on the service.

Affected Systems

Oracle Corporation’s TimesTen In‑Memory Database, version 26.1.1.1.0, is the only documented affected product. No other releases are explicitly listed.

Risk and Exploitability

The CVSS base score is 4.3, indicating a medium impact limited to availability. The EPSS score is less than 1%, implying a low likelihood of exploitation in the near term. The vulnerability is not currently listed in CISA’s KEV catalog, so there is no evidence of active exploitation. Attackers would need only low network privileges and the ability to reach the exposed HTTPS endpoint of the Kubernetes Operator, so the damage is restricted to a partial service outage.

Generated by OpenCVE AI on August 4, 2026 at 03:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security advisory for an available patch or update for TimesTen 26.1.1.1.0 and apply it promptly.
  • Restrict network access to the TimesTen Kubernetes Operator to trusted hosts or networks and enforce least privilege.
  • Disable the exposed HTTPS endpoint if it is not required, or configure firewall rules to block unauthorized IP ranges.

Generated by OpenCVE AI on August 4, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service in Oracle TimesTen In‑Memory Database Kubernetes Operator

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Improper Resource Handling in Oracle TimesTen In‑Memory Database Kubernetes Operator

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service via Improper Resource Handling in Oracle TimesTen In‑Memory Database Kubernetes Operator

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:09:22.733Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60410

cve-icon Vulnrichment

Updated: 2026-07-24T16:09:18.815Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption