Impact
Vulnerability in Oracle Helidon 3.0.0‑3.2.17's Imperative Web Server permits an unauthenticated attacker with network access over HTTPS to read a subset of data exposed by the server; the issue is a weakness identified as CWE‑284 (Improper Authorization). Attackers can obtain confidential information through the web interface without needing credentials, leading to a confidentiality breach, and the flaw does not affect integrity or availability. This vulnerability allows unauthenticated access to sensitive data via the HTTPS interface.
Affected Systems
Oracle Helidon 3.0.0 through 3.2.17, distributed as part of Oracle Fusion Middleware, are affected. Only versions prior to 3.2.18 contain the flaw.
Risk and Exploitability
CVSS 3.1 base score 5.3 reflects moderate confidentiality impact. EPSS score below 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Any entity that can reach the Helidon instance over HTTPS can trigger the exploit without credentials or prior compromise, allowing them to read a limited set of data.
OpenCVE Enrichment