Executive brief
Oracle TimesTen In-Memory Database is a high-performance database used for applications requiring extremely fast data access. A vulnerability in the ttcserver component allows an attacker on the same local network to crash the database or cause it to stop responding. This results in a complete denial of service, potentially disrupting business operations that rely on real-time data processing.
Technical details
A vulnerability exists in the ttcserver component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. The flaw is easily exploitable by an unauthenticated attacker located on the same physical communication segment (adjacent network) as the database server. Successful exploitation allows the attacker to trigger a hang or a frequently repeatable crash, leading to a complete loss of availability (Denial of Service). The vulnerability is tracked as CVE-2026-60411 with a CVSS 3.1 base score of 6.5. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle TimesTen In-Memory Database 26.1.1.1.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-60411 was published to the NVD.