CVE-2026-60405: Infoleak
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60405?
The severity of CVE-2026-60405 is rated low with a score of 3.8.
What types of attacks can exploit CVE-2026-60405?
CVE-2026-60405 can be exploited by low privileged attackers who have logon access to the infrastructure.
How can I mitigate CVE-2026-60405?
To mitigate CVE-2026-60405, ensure that you apply the latest security patches for Oracle TimesTen In-Memory Database.
Which version of Oracle TimesTen In-Memory Database is affected by CVE-2026-60405?
The affected version of Oracle TimesTen In-Memory Database for CVE-2026-60405 is 26.1.1.1.0.
What is the nature of CVE-2026-60405?
CVE-2026-60405 is classified as an infoleak vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database.