Impact
A vulnerability in the Helidon product of Oracle Fusion Middleware’s imperative web server component allows an unauthenticated HTTP attacker to modify, insert, or delete data and to read a subset of accessible data. Successful attacks require human interaction from a person other than the attacker and may impact additional products. The flaw affects Helidon versions 4.0.0 through 4.4.1 and can lead to integrity and confidentiality breaches due to lack of proper access controls.
Affected Systems
Oracle Helidon, versions 4.0.0 through 4.4.1, in Oracle Fusion Middleware. These releases are affected; later releases are not listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.1 indicates moderate severity with low confidentiality and integrity impact. EPSS score < 1% indicates an extremely low but non-zero probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. Attackers exploit the flaw via unauthenticated HTTP traffic; however, the description indicates that successful attacks require human interaction from a person other than the attacker, suggesting possible social engineering or gateway involvement. The scope may change because successful exploitation in Helidon may affect other products running in the same environment.
OpenCVE Enrichment