CRITICAL🇵🇱 Wersja polska

CVE-2026-60402

CVSS 9.9v3.1pub. 2026-07-21upd. 2026-07-31

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Oracle Timesten In Memory Database

    APP
    Oracle
    26.1.1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSContainer
CWE
References

Related vulnerabilities

CVE-2019-11835CRITICAL9.8PL ✓same product

Dostęp poza zakresem pamięci w cJSON związany z komentarzami wieloliniowymi

CVE-2019-11834CRITICAL9.8PL ✓same product

cJSON: out-of-bounds access przez znak \x00 w literale tekstowym

CVE-2018-11058CRITICAL9.8PL ✓same product

Buffer Over-Read w RSA BSAFE podczas parsowania danych ASN.1

CVE-2021-41772HIGH7.5same product

Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive c...

CVE-2021-29923HIGH7.5same product

Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, ...