Executive brief
A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with low-level access to the network can exploit this flaw to gain unauthorized read access to certain database information. While the attacker cannot modify or delete data, this could lead to the exposure of sensitive business or operational information.
Technical details
An information disclosure vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation allows the attacker to achieve unauthorized read access to a subset of data accessible to the TimesTen In-Memory Database. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting a partial impact on confidentiality with no impact on integrity or availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle TimesTen In-Memory Database 26.1.1.1.0
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.