Impact
An unauthenticated attacker who can reach Oracle Helidon over HTTP can cause the server to perform unauthorized update, insert or delete operations on Helidon-accessible data and can also read a subset of that data. The flaw appears in the Imperative Web Server component and affects confidentiality and integrity but not availability.
Affected Systems
The affected product is Oracle Helidon version 3.0.0 through 3.2.17. These releases contain the Imperative Web Server component that is vulnerable. Versions newer than 3.2.17 are not affected.
Risk and Exploitability
The attack vector is network based (AV:N) and authentication is not required, so an attacker with network access can exploit the flaw easily. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploits in the wild at this time. Nevertheless, the potential for unauthorized data loss or alteration warrants prompt attention.
OpenCVE Enrichment