Impact
Oracle Helidon, part of Oracle Fusion Middleware, suffered an improper access control flaw in its Imperative Web Server component. The vulnerability, documented as affecting versions 3.0.0 through 3.2.17, permits a low‑privileged attacker who can reach the server over HTTP to update, insert, delete, or read Helidon‑accessible data that should be protected. This flaw maps to CWE‑284 and results in confidentiality and integrity impacts as reflected by the CVSS vector, which shows low but non‑zero effects for both dimensions.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. These releases are part of Oracle Fusion Middleware and are supported on the indicated version range; earlier and later versions are not known to be impacted.
Risk and Exploitability
The CVSS base score of 4.2 classifies the flaw as medium severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of active exploitation. The attack requires network reachability to the Helidon instance over HTTP and the ability to act with low privileges – for example, a local user or a compromised host. Successful exploitation enables an attacker to alter or read Helidon data, undermining business data integrity and confidentiality.
OpenCVE Enrichment