Impact
Oracle Helidon’s Imperative Web Server has a flaw that permits an unauthenticated network attacker with HTTP access to modify or read data without proper authorization. The vulnerability can lead to unauthorized updates, inserts or deletes, or reads of Helidon‑protected data, compromising confidentiality and integrity. The description of this vulnerability has been updated; consult the official advisory for the latest details.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. No other products or extensions are listed as directly impacted, though the vulnerability may indirectly affect other applications that rely on Helidon services.
Risk and Exploitability
The CVSS v3.1 score of 6.1 indicates a moderate severity with moderate exploitation difficulty (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Exploitation requires network access via HTTP and a secondary human interaction, meaning an attacker alone cannot fully compromise the system without cooperation from another user. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog; thus no known public exploits or high exploit probability are reported at this time.
OpenCVE Enrichment