Impact
Oracle Helidon versions 4.0.0 through 4.4.1 include a vulnerability in its Imperative Web Server component that allows an unauthenticated user with network access to HTTP traffic to read a subset of data exposed by Helidon. The flaw provides limited confidentiality exposure (low impact) but still permits unauthorized extraction of information without any authentication or additional privileges. This is a CWE-284 Improper Access Control flaw.
Affected Systems
The vulnerability affects Oracle Helidon versions 4.0.0 through 4.4.1. No later releases are currently listed as affected. The product is part of Oracle Fusion Middleware and is distributed under the Helidon brand.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates medium severity and relies solely on network access (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). The associated EPSS score is less than 1% and the vulnerability is not included in CISA's KEV catalog, meaning there are no known publicly disclosed exploits at this time. However, an attacker who scans for exposed Helidon services could potentially exploit the flaw by simply connecting over HTTP. Based on the description, it is inferred that the attack vector is via unauthenticated HTTP traffic.
OpenCVE Enrichment