Impact
Helidon, part of Oracle Fusion Middleware, contains a flaw in the Imperative Web Server component that permits unauthenticated attackers to send HTTP requests from any network location. The vulnerability allows an attacker to inject, modify, delete, or read Helidon‑exposed data without authentication, resulting in integrity and confidentiality loss as described. The weakness can also affect associated Fusion Middleware products that rely on Helidon, due to the scope change. This is associated with CWE-284 (Improper Access Control).
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.0 are affected by this vulnerability. The flaw may also impact other Oracle Fusion Middleware components that depend on Helidon, creating potential wider exposure beyond Helidon itself.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates a high severity vulnerability. The EPSS score of < 1% and the flaw has not been listed in the CISA KEV catalog, suggesting limited public exploitation to date. The likely attack vector is network‑based, via HTTP requests to the Helidon service, and the flaw is easily exploitable since no authentication is required. Successful exploitation would allow an attacker to compromise Helidon and potentially affect other downstream services, resulting in unauthorized data modification and partial disclosure.
OpenCVE Enrichment