Impact
A flaw in the Oracle Helidon Imperative Web Server allows unauthenticated HTTP requests to create, delete, or modify critical data that the server manages. The vulnerability results in a high integrity impact, as it enables an attacker to alter or remove information without authorization. It is classified as a missing authorization weakness (CWE-284) and could lead to unauthorized manipulation of application data.
Affected Systems
Oracle Helidon, versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1 are impacted. These releases include the Imperative Web Server component where the flaw resides.
Risk and Exploitability
The CVSS v3.1 Base Score of 5.9 indicates a moderate severity primarily affecting integrity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP requests that can be sent from any network with access to the Helidon HTTP interface, requiring no authentication but necessitating legitimate HTTP traffic. If exploitation succeeds, an attacker could modify or delete any data processed by the server.
OpenCVE Enrichment