Impact
A flaw in the Helidon Imperative Web Server allows an unauthenticated attacker with network access via HTTP to read and potentially alter Helidon accessible data, affecting versions 3.0.0 through 3.2.17. The vulnerability enables unauthorized update, insert, or delete operations, thereby compromising the confidentiality and integrity of the data exposed by the web service. The weakness is an improper access control flaw (CWE‑284).
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected by this CVE. Earlier and later releases are not reported as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate to high risk, and the attack scenario requires only a network connection to the HTTP endpoint. Exploit difficulty is high (acquisition of the vulnerability is not trivial), and the EPSS score is less than 1%, indicating a very low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no documented active exploits yet. Nevertheless, an unauthenticated attacker who can reach Helidon over HTTP can exploit this flaw, potentially leading to unauthorized data modification and exposure.
OpenCVE Enrichment