Impact
An attacker with network access via HTTP can exploit a flaw in Oracle Helidon's Imperative Web Server that bypasses access controls. The vulnerability is easily exploitable and permits a low‑privileged attacker to gain unauthorized access to critical data or complete access to all Helidon accessible data, as well as insert, update, or delete data that should be restricted to higher‑privilege users. Because the flaw exists in Helidon, the scope change can affect additional products, allowing the attacker to achieve higher privileges across Helidon‑accessible data.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The vulnerability resides in the Helidon product’s imperative web server component.
Risk and Exploitability
The CVSS v3.1 score of 8.5 reflects a high‑severity finding, with a network attack vector, low attack complexity, low privilege required, and no required user interaction. The EPSS score of <1% indicates a very low but non‑zero probability of exploitation, while the absence of a KEV listing does not diminish the inherent risk. The attack is straightforward for an adversary able to send HTTP requests to the target; by exploiting the flaw, the attacker can change the scope of access controls and gain higher privileges, thereby compromising confidentiality and potentially integrity of Helidon data.
OpenCVE Enrichment