Impact
A difficult‑to‑exploit flaw exists in Oracle Helidon’s Imperative Web Server that permits an unauthenticated attacker with HTTP network access to compromise the server. The vulnerability enables the attacker to read critical data or gain full access to any data that the Helidon instance makes available. The issue is an authorization bypass that changes scope, potentially affecting additional applications that rely on Helidon.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The Helidon product is part of Oracle Fusion Middleware and the flaw resides in its web server component.
Risk and Exploitability
The CVSS v3.1 base score of 6.8 indicates a moderate severity, with a network attack vector, high complexity, no required privileges, and no user interaction, while changing scope to affect confidentiality. The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is remote HTTP access, allowing potential unauthorized data exposure if the vulnerability is reached.
OpenCVE Enrichment