Impact
Based on the updated CVE description, the Helidon component of Oracle Fusion Middleware contains a flaw in its Imperative Web Server that allows an unauthenticated attacker with HTTP network access to compromise the application. Versions 3.0.0 through 3.2.17 are affected. A successful exploitation can lead to unauthorized access to critical data, complete access to all Helidon‑served data, and unauthorized update, insert or delete operations on some Helidon data. The CVSS base score of 8.2 indicates high impact on confidentiality and integrity. The vulnerability stems from an authentication and authorization weakness, identified as CWE-284.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17, part of Oracle Fusion Middleware's Imperative Web Server, are affected. No later versions are listed.
Risk and Exploitability
Based on the updated description, it is inferred that the likely attack vector is via unauthenticated HTTP requests from any network location. The vulnerability has a high severity score of 8.2 and can be exploited from any network location with HTTP access, with no required authentication or user interaction. The EPSS score of <1% indicates a very low probability of exploitation, yet the easily exploitable nature and the potential for broad data compromise make it a significant risk. The vulnerability is not yet listed in the CISA KEV catalog, but the impact and low attack barrier warrant immediate attention.
OpenCVE Enrichment