Executive brief
A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with low-level access to the underlying infrastructure could exploit this flaw to gain unauthorized read access to certain database information. While the direct impact is limited to data confidentiality, the breach could potentially affect other integrated systems within the environment.
Technical details
This vulnerability affects the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. It is classified as an information disclosure flaw that is easily exploitable by an attacker with local logon access to the infrastructure where the database executes. The exploit results in a scope change (S:C), meaning the impact can extend beyond the immediate database component to other products in the environment. Successful exploitation allows unauthorized read access to a subset of accessible data. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle TimesTen In-Memory Database 26.1.1.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published