Impact
Vulnerability in the Helidon product of Oracle Fusion Middleware, the Imperative Web Server component, allows unauthenticated attackers with network access via HTTP to compromise Helidon and trigger a repeatable crash that results in a denial-of-service. Affected are Helidon versions 1.0.0 through 1.4.19; the flaw impacts availability only, without affecting confidentiality or integrity, and is classified as CWE-284.
Affected Systems
Oracle Helidon versions 1.0.0 through 1.4.19 are affected, as identified by the CNA Oracle Corporation. This includes the Helidon Imperative Web Server component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity for availability. Because the vulnerability is exploitable over the network without authentication and the EPSS score is less than 1%, the likelihood of exploitation is low, though not zero. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. An attacker can initiate the denial of service by sending specially crafted HTTP traffic, leading to system unavailability. The lack of authentication requirement and the network exposure make the attack vector straightforward for any adversary with access to the Helidon network interface.
OpenCVE Enrichment