Impact
A vulnerability exists in Oracle Helidon’s Imperative Web Server component, allowing any unauthenticated user with network access over HTTP to create, delete, or modify critical data and to obtain full access to all Helidon-served data. These actions can also lead to a partial denial of service. The flaw carries a high confidentiality and integrity impact, and a moderate availability impact, as reflected in its CVSS 3.1 score of 9.4.
Affected Systems
Oracle Helidon Imperative Web Server, affected versions 4.0.0 through 4.4.1.
Risk and Exploitability
The flaw is reachable via ordinary HTTP traffic and requires no authentication, making it readily exploitable by anyone with network reach to the Helidon service. The CVSS 3.1 base score of 9.4 reflects severe impact on confidentiality and integrity and a lower but still significant availability impact. An EPSS score of < 1 % indicates the current probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is unauthenticated HTTP traffic targeting the Helidon server. The vulnerability affects Helidon releases 4.0.0‑4.4.1.
OpenCVE Enrichment