Impact
A vulnerability exists in Oracle Helidon (versions 1.0.0 through 1.4.19, and 3.0.0 through 3.2.17) that allows an unauthenticated network attacker to send HTTP requests and compromise the Helidon service. A successful exploitation results in a full takeover of the Helidon instance, providing the attacker with full confidentiality, integrity, and availability impact as reflected in the CVSS 3.1 base score of 9.8.
Affected Systems
The affected product is Oracle Helidon, specifically the Imperative Web Server component of Oracle Fusion Middleware. Versions 1.0.0 through 1.4.19 and 3.0.0 through 3.2.17 are affected. No other versions beyond those ranges are listed as vulnerable.
Risk and Exploitability
The CVSS score indicates a high likelihood of severe impact. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the EPSS score is 0.00473 (approximately 0.47%), indicating a very low but nonzero exploitation probability. Based on the description, the attack vector is a network-based HTTP request accepted without authentication, enabling an attacker to trigger the remote code execution that leads to system takeover.
OpenCVE Enrichment