Impact
A flaw in the Imperative Web Server of Oracle Helidon versions 4.0.0 through 4.4.1 permits an attacker who can reach the HTTP interface to alter or read Helidon data without proper authorization. The attacker does not need a user interface or elevated credentials; merely low‑privileged network access suffices to send crafted HTTP requests that bypass the access controls, resulting in confidentiality and integrity impacts.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 in Oracle Fusion Middleware are the affected assets. The vulnerability resides in the Imperative Web Server component and can be exploited by any host able to connect to the Helidon HTTP endpoint.
Risk and Exploitability
The base CVSS score of 5.4 indicates moderate severity, with low but measurable confidentiality and integrity impact and no availability impact. The EPSS score is below 1 %, implying a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread, actively exploited instances are known. The attack vector is over the network via HTTP, requiring only low‑privileged access, which makes the flaw easily exploitable by any threat actor able to send crafted requests to Helidon.
OpenCVE Enrichment