Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TimesTen In‑Memory Database component ttcserver contains a resource exhaustion weakness that allows an unauthenticated attacker with physical access to the database's communication segment to cause a hang or frequent crash, resulting in a complete denial of service. This flaw is identified as CWE-400. The vulnerability permits an attacker to disrupt availability without authentication, emphasizing its impact on service continuity. The reported CVSS 3.1 base score of 6.5 indicates moderate severity with a high impact on availability.

Affected Systems

Oracle Corporation TimesTen In‑Memory Database version 26.1.1.1.0 is the only product version identified as affected.

Risk and Exploitability

The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the current landscape. The likely attack vector is physical access to the communication segment that the database uses, inferred from the description. Once exploited, the attacker gains the ability to cause service outages, potentially interrupting critical database operations. The CVSS score of 6.5 reflects the moderate risk, but the limited exploitation likelihood mitigates the overall threat level for environments that restrict physical access.

Generated by OpenCVE AI on August 2, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a newer, non‑affected version of TimesTen In‑Memory Database.
  • Restrict physical access to the communication segment used by the TimesTen instance and enforce hardening of the physical network interface.
  • Monitor the database for recurring hang or crash events, and review system logs for signs of attempted exploitation.

Generated by OpenCVE AI on August 2, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title TimesTen In‑Memory Database Denial of Service via Physical Communication Segment Access

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:08:12.140Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60411

cve-icon Vulnrichment

Updated: 2026-07-24T16:08:05.723Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption