Impact
Oracle Helidon’s Imperative Web Server contains an improper access control flaw (CWE‑285) that allows an unauthenticated attacker with network access via HTTP to modify data. Supported Helidon versions 3.0.0 through 3.2.18 are affected. The vulnerability can be triggered without the attacker needing administrative privileges, but it does require human interaction with a user other than the attacker. Successful exploitation can lead to unauthorized update, insert or delete operations, as well as read access to a subset of Helidon data. Because the flaw resides in Helidon, attacks may also affect other Oracle products that depend on it, resulting in a scope change.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.18 are affected. Users running those versions, particularly those exposing the service to external networks, are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 6.1 indicates moderate severity. The attack vector is network (AV:N) with low complexity (AC:L), no authentication required (PR:N), user interaction needed (UI:R), and scope change (S:C). The EPSS score of < 1% reflects a very low probability of exploitation. While the vulnerability is not listed in CISA KEV, the potential for unauthorized data modification and read access makes it essential to address promptly.
OpenCVE Enrichment