Impact
The vulnerability in the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, can be easily exploited by an unauthenticated attacker with network access via HTTP. The flaw allows the attacker to perform unauthorized updates, inserts or deletes on Helidon‑accessible data and to read a subset of that data. This represents an authorization bypass identified as CWE‑284, resulting in a loss of confidentiality and integrity for the affected data.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.18 are affected. The vulnerability applies to all deployments of the Helidon Imperative Web Server component within that version range. No other vendors or products are reported as impacted.
Risk and Exploitability
The CVSS base score of 7.2 reflects a high severity with low complexity and no user interaction, while the attack vector is network‑based. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Although widespread exploitation remains uncertain, the potential for unauthorized data modification and read presents significant risk for exposed Helidon deployments.
OpenCVE Enrichment