Impact
This vulnerability arises from insufficient access controls in the Helidon Imperative Web Server. An attacker who can reach the vulnerable instance over the network via HTTP can perform unauthorized creation, deletion, or modification of critical data, gain full access to any data served by Helidon, and trigger a partial denial of service that affects availability. The flaw directly impacts confidentiality, integrity, and availability for the affected system without requiring prior authentication.
Affected Systems
Oracle Helidon versions 3.0.0 to 3.2.17 are affected. All installations within this version range should verify that no insecure defaults or misconfigurations remain and that the product is not running as a privileged user if unnecessary.
Risk and Exploitability
The CVSS base score of 9.4 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a very low exploitation probability at present. The flaw is characterized as easily exploitable and does not appear in the CISA KEV catalog, implying no widespread known attacks yet. An unauthenticated attacker only needs network connectivity to the Helidon HTTP service to exploit the weakness, potentially achieving complete access to Helidon‑served data and partial denial of service.
OpenCVE Enrichment