Impact
A flaw in Oracle Helidon's Imperative Web Server allows a low‑privileged attacker who has logged onto the host where Helidon runs to compromise the service. Successfully exploiting the vulnerability can grant unauthorized access to critical data or all data exposed by Helidon, as well as permitting unauthorized update, insert or delete operations on that data.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. No other releases are listed as vulnerable.
Risk and Exploitability
The Core Vulnerability Severity Score of 6.1 indicates moderate risk. The attack vector is local (AV:L), requiring low attack complexity (AC:L) and low privileges (PR:L) with no user interaction needed. The EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation. Because the flaw is not cataloged in CISA KEV, there are no known widespread attacks at this time. However, an attacker who has physical or remote console access to the Helidon host could leverage the vulnerability to read or modify Helidon‑exposed data, providing a clear, actionable threat for systems where Helidon runs under users with insufficiently restricted privileges.
OpenCVE Enrichment