Impact
The Helidon product within Oracle Fusion Middleware contains a flaw in its Imperative Web Server component that allows an unauthenticated attacker who can reach the service over HTTP to compromise the application. A successful exploit can lead to unauthorized creation, deletion, or modification of critical data and also provides full access to all Helidon‑accessible data, resulting in significant confidentiality and integrity losses. This vulnerability affects Helidon versions from 3.0.0 to 3.2.17 and is a CWE‑284 authentication bypass flaw.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The vulnerability resides in the Helidon Imperative Web Server component used in Oracle Fusion Middleware.
Risk and Exploitability
The CVSS base score of 9.1 marks this vulnerability as critical. The exploit can be carried out over an open HTTP connection with no authentication or user interaction, indicating a low barrier to entry for attackers. The EPSS score of < 1% suggests that exploitation is currently rare, but the remote nature and severe impact still necessitate prompt action. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS and readily available attack vector emphasize the need for timely remediation.
OpenCVE Enrichment