Impact
The vulnerability is an unauthenticated access control flaw in Oracle Helidon’s Imperative Web Server component, permitting attackers to send HTTP requests without authentication to read, insert, update, or delete data exposed by the server. The description specifies that exploitation can occur without user interaction and results in confidentiality and integrity loss for Helidon‑managed data. The weakness maps to improper access control (CWE-284).
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The CPE strings confirm that all releases in that range contain the flaw. The advisory notes that the problem may also impact other Oracle Fusion Middleware products that incorporate Helidon, although no specific additional products are listed.
Risk and Exploitability
The CVSS 3.1 base score of 9.3 classifies the issue as critical. The vector indicates a network‑based exploitation path with no authentication or user interaction required. The EPSS score is <1%, showing a very low yet nonzero probability of real‑world exploitation, but because the vulnerability is listed in no KEV catalog, it has not yet been openly exploited. Nonetheless, the high severity and straightforward attack path warrant urgent remediation. Based on the description, the likely attack vector is HTTP requests coming from external networks, implying that organizations exposing Helidon to untrusted networks should immediately act.
OpenCVE Enrichment