Impact
A flaw in Oracle Helidon versions 3.0.0 through 3.2.18, within the Imperative Web Server component, permits an unauthenticated attacker to reach the web server over HTTP and modify data stored by the application. This lack of authentication and authorization control, corresponding to CWE-284, allows direct alteration of protected data. The vulnerability is exercised through HTTP requests that do not require any authentication, and successful exploitation grants the attacker the ability to update, insert or delete protected data, impacting the integrity of the system. The CVSS 3.1 base score of 5.3 reflects a moderate difficulty to exploit and an impact limited to data integrity, with no confidentiality or availability impact. The CVSS vector indicates an network attack vector, low attack complexity, no privileges or user interaction, and an overall unchanged scope.
Affected Systems
Oracle Corporation Helidon Fusion Middleware versions 3.0.0 through 3.2.18 are affected. No additional vendor or product versions are listed in the vulnerability report.
Risk and Exploitability
The CVSS score of 5.3 positions this issue in the moderate severity range, and the EPSS score of <1% indicates a very low likelihood of public exploitation. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP, where an attacker can craft and send requests without any form of authentication, exploiting the missing access control. Successful attacks can lead to unauthorized data modification, compromising business processes and data integrity.
OpenCVE Enrichment