Impact
A flaw in the Kubernetes Operator component of Oracle TimesTen In‑Memory Database allows a low‑privileged attacker with network access via HTTPS to induce a partial denial of service. The vulnerability stems from improper resource handling, which is inferred to be a resource‑exhaustion weakness corresponding to CWE‑400. An attacker who succeeds can cause the database to become partially unavailable, disrupting availability for users that rely on the service.
Affected Systems
Oracle Corporation’s TimesTen In‑Memory Database, version 26.1.1.1.0, is the only documented affected product. No other releases are explicitly listed.
Risk and Exploitability
The CVSS base score is 4.3, indicating a medium impact limited to availability. The EPSS score is less than 1%, implying a low likelihood of exploitation in the near term. The vulnerability is not currently listed in CISA’s KEV catalog, so there is no evidence of active exploitation. Attackers would need only low network privileges and the ability to reach the exposed HTTPS endpoint of the Kubernetes Operator, so the damage is restricted to a partial service outage.
OpenCVE Enrichment