Impact
Oracle Helidon versions 1.0.0 through 1.4.18, 3.0.0 through 3.2.17, and 4.0.0 through 4.4.1 contain a flaw in the Imperative Web Server that enables an attacker with low‑level network access over HTTPS to create, delete, or modify data. The escalation allows unauthorized access to all data that Helidon serves, thereby compromising confidentiality and integrity for affected installations.
Affected Systems
The vulnerability affects Oracle Helidon versions 1.0.0 through 1.4.18, 3.0.0 through 3.2.17, and 4.0.0 through 4.4.1 running within Oracle Fusion Middleware. No other releases are listed as affected.
Risk and Exploitability
With a CVSS score of 8.1 the flaw is considered high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. The attack vector involves an attacker with network access over HTTPS crafting requests to the Helidon server to perform unauthorized operations.
OpenCVE Enrichment