Impact
The vulnerability resides in Oracle Helidon's Imperative Web Server component, affecting releases 3.0.0 through 3.2.17. An unauthenticated attacker with network connectivity over HTTP can bypass authentication and gain unauthorized access to any data the server serves. The flaw permits read‑only access to all data exposed by the Helidon service, potentially exposing sensitive or critical information. No user credentials or privileged access are required, and the vulnerability is classified as an authentication bypass with a high confidentiality impact.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. No other Helidon releases or related Oracle Fusion Middleware products are listed as vulnerable in the provided data.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 marks the issue as high severity, with a network attack vector, low attack complexity, and no privileges required. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog, indicating no known active exploits. Nonetheless, the straightforward bypass and lack of authentication make it an attractive target for opportunistic attackers.
OpenCVE Enrichment