Impact
The TimesTen In‑Memory Database component ttcserver contains a resource exhaustion weakness that allows an unauthenticated attacker with physical access to the database's communication segment to cause a hang or frequent crash, resulting in a complete denial of service. This flaw is identified as CWE-400. The vulnerability permits an attacker to disrupt availability without authentication, emphasizing its impact on service continuity. The reported CVSS 3.1 base score of 6.5 indicates moderate severity with a high impact on availability.
Affected Systems
Oracle Corporation TimesTen In‑Memory Database version 26.1.1.1.0 is the only product version identified as affected.
Risk and Exploitability
The EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the current landscape. The likely attack vector is physical access to the communication segment that the database uses, inferred from the description. Once exploited, the attacker gains the ability to cause service outages, potentially interrupting critical database operations. The CVSS score of 6.5 reflects the moderate risk, but the limited exploitation likelihood mitigates the overall threat level for environments that restrict physical access.
OpenCVE Enrichment