Impact
The Helidon Imperative Web Server component of Oracle Helidon contains an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to gain unauthorized update, insert, or delete rights on data exposed by the service, as well as read access to a subset of that data. Consequently, confidentiality and integrity of Helidon‑managed data are compromised, while availability remains unaffected.
Affected Systems
This vulnerability affects Oracle Helidon versions 3.0.0 through 3.2.17, which are part of Oracle Fusion Middleware. The flaw is present when the Helidon Imperative Web Server is exposed over HTTP. No other Oracle Helidon releases or related products are known to be impacted.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate severity, with low attack complexity, low required privileges, and no user interaction. The EPSS score of < 1% and absence from the CISA KEV catalog suggest that exploitation risk is largely driven by the ease of sending crafted HTTP requests to a non‑authenticated endpoint that lacks proper access control. A threat actor could send HTTP requests targeting the vulnerable endpoint to obtain unauthorized data manipulation and read permissions, thereby violating confidentiality and integrity.
OpenCVE Enrichment