Impact
A vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server) affects supported versions 3.0.0 through 3.2.17. The flaw allows an unauthenticated attacker with network access via HTTP to compromise Helidon. Successful exploitation can result in takeover of the Helidon instance, compromising confidentiality, integrity, and availability. The vulnerability is categorized as CWE-284.
Affected Systems
Affected product is Oracle Helidon, with affected versions 3.0.0 through 3.2.17. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.8 and the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H highlight a critical risk, reachable over the network with low attack complexity. The EPSS score of less than 1% indicates that real‑world exploitation is currently rare, but the absence of authentication and public exposure of the HTTP interface elevate its practical danger. The vulnerability is not listed in CISA’s KEV catalog, which does not negate the need for remediation.
OpenCVE Enrichment