Executive brief
A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with high-level administrative access to the underlying infrastructure could exploit this flaw to view, modify, or delete sensitive database records. Additionally, an exploit could cause a partial service outage, potentially impacting other integrated business systems.
Technical details
This vulnerability affects the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. It is classified as a local exploit requiring high privileges (PR:H), meaning the attacker must already have significant access to the infrastructure where the database is running. The flaw is characterized by a 'scope change' (S:C), indicating that a successful exploit can impact components beyond the immediate database environment. Attackers can achieve unauthorized read, update, insert, or delete access to database data, as well as cause a partial denial of service (DoS). The vulnerability is easily exploitable once the prerequisite access is obtained.
Affected products
- Oracle TimesTen In-Memory Database 26.1.1.1.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published