Impact
A flaw in Oracle Helidon’s Imperative Web Server component of Oracle Fusion Middleware permits an unauthenticated attacker with network access over HTTP to read protected data. The vulnerability is effective on Helidon versions 3.0.0 through 3.2.19 and is not present in 3.2.20 or newer. As a result, an attacker can gain unauthorized read access to a subset of resources managed by Helidon, impacting confidentiality but not affecting integrity or availability.
Affected Systems
The flaw affects Oracle Helidon, specifically the Helidon Imperative Web Server component in Oracle Fusion Middleware. Supported versions that are vulnerable are 3.0.0 through 3.2.19; versions 3.2.20 and later are not affected.
Risk and Exploitability
The CVSS v3.1 base score of 3.7 indicates a low overall risk, with only confidentiality impact. The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a direct network reachability via an HTTP interface exposed to the attacker. No local access or privilege escalation is required. Given the low severity, the probability of exploitation is presumably low, but the vulnerability remains a potential risk for systems that expose Helidon services to untrusted networks.
OpenCVE Enrichment