Impact
Oracle Helidon’s Imperative Web Server contains a vulnerability that enables a low-privilege attacker with network access via HTTP to compromise the application. The flaw is difficult to exploit, as indicated by a high attack complexity factor, yet it remains achievable for an attacker possessing only basic network connectivity. Successful exploitation results in a complete takeover, violating confidentiality, integrity, and availability; the CVSS 3.1 base score of 7.5 reflects this high severity. The listed CWE-284 identifier points to a potential improper access control weakness, although the root cause is not explicitly detailed in the description.
Affected Systems
Affected Oracle Helidon versions span 1.0.0 through 1.4.18 and 3.0.0 through 3.2.17. Versions beyond 3.2.17, such as 3.2.18, are not affected. Helidon is part of Oracle Fusion Middleware and is delivered under the Helidon brand.
Risk and Exploitability
The vulnerability is network-based (AV:N) with a high attack complexity (AC:H) and requires low privileges (PR:L). Its impact on confidentiality, integrity, and availability (C:H/I:H/A:H) is high, matching the CVSS base score of 7.5. The EPSS score is reported as less than 1%, indicating a low overall likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The identified weakness (CWE-284) suggests improper access control as a possible root; however, the specific attack surface or vulnerable component is not detailed in the description.
OpenCVE Enrichment