Impact
The Helidon Imperative Web Server component in Oracle Fusion Middleware, for versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1, contains a vulnerability that allows an unauthenticated attacker with network access via HTTP to perform unauthorized creation, deletion or modification of data. The flaw can lead to both confidentiality and integrity violations, giving the attacker full control over all Helidon accessible data.
Affected Systems
Affected: Oracle Helidon versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1, part of Oracle Fusion Middleware. The product is accessed over HTTP on the network.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 reflects a medium‑to‑high severity risk. Exploitation requires network connectivity to the Helidon service over HTTP and no user interaction, though the high attack complexity indicates the issue is difficult to exploit. The EPSS score is less than 1%, and the flaw is not listed in the CISA KEV catalog, indicating no confirmed active exploitation yet. Nevertheless, because the vulnerability permits full unauthorized data manipulation, it poses a serious threat to affected deployments.
OpenCVE Enrichment