Impact
The Helidon product of Oracle Fusion Middleware provides an Imperative Web Server that contains a flaw allowing unauthenticated attackers to read a subset of data exposed over HTTP. The vulnerability is a breach of authorization, as indicated by CWE-284, and results in information disclosure. The affected version range ends at 3.2.17, so newer releases such as 3.2.18 are not impacted.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The product is part of Oracle Fusion Middleware and can be deployed in environments where the Helidon HTTP endpoint is reachable over the network.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 classifies the issue as moderate severity with a confidentiality impact. The vector indicates a network‑based attack, low complexity, no privileges, and no user interaction, rendering the flaw easily exploitable if the Helidon service is exposed. The EPSS score is reported as < 1%, suggesting a low overall probability of exploitation in general populations; the vulnerability is not included in CISA’s KEV catalog. Attackers on the same network segment or who can reach the Helidon endpoint can leverage the flaw without additional credentials to obtain sensitive data exposed by the server.
OpenCVE Enrichment