Impact
Vulnerabilities in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server) affect supported versions 4.0.0 through 4.4.1. The flaw allows an unauthenticated attacker with network access via HTTP to compromise Helidon, enabling unauthorized update, insert or delete operations on some Helidon–accessible data and unauthorized read access to a subset of such data. The impact is limited to confidentiality and integrity, with no availability effects, as reflected in a CVSS 3.1 base score of 6.5.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected by this issue. No other Helidon releases or Oracle products are listed as impacted.
Risk and Exploitability
Because authentication is not required and the attack vector is publicly reachable over HTTP, the risk of exploitation is moderate to high. The CVSS score of 6.5 indicates a significant impact potential, while the EPSS score of <1% indicates a very low probability of exploitation. The absence of a KEV listing does not diminish the need for immediate remediation. An attacker could exploit this flaw to alter Helidon data or access sensitive information with no credential required, representing a serious threat for systems exposed to the internet or untrusted networks.
OpenCVE Enrichment