Impact
Helidon, an Oracle Fusion Middleware component that hosts an Imperative Web Server, has an access control flaw that allows an unauthenticated attacker with network reach to the HTTP interface to create, delete, or modify any data the Helidon process can access. This results in a total loss of confidentiality and integrity for all Helidon‑served data, as the attacker can view or alter every piece of information exposed by the service.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are listed as vulnerable in the advisory. No other products or versions are mentioned, and the CPE data confirms that Helidon 4.5.0 is a separate variant not included in the affected range.
Risk and Exploitability
The flaw is remotely exploitable via ordinary HTTP traffic; the attacker needs only network access to the Helidon instance, with no authentication or privilege required. The EPSS score of less than 1% indicates that widespread exploitation is currently unlikely, but the absence of authentication means that once an attacker can reach the service, the attack can be carried out with minimal effort. The CVSS base score of 9.1 highlights a severe impact on confidentiality and integrity, and the vulnerability is not listed in the CISA KEV catalog, so organizations must assess and mitigate the risk themselves.
OpenCVE Enrichment