Impact
A flaw in the Imperative Web Server component of Oracle Helidon allows an unauthenticated attacker with network access to read a subset of data that is normally protected. The vulnerability results in the disclosure of sensitive information, exclusively affecting confidentiality and leaving integrity and availability untouched.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17, part of Oracle Fusion Middleware, are affected. The affected component is the Imperative Web Server.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates a medium-risk vulnerability that impacts confidentiality. An attacker can exploit the flaw over the network using HTTP without any authentication or privileges. The EPSS score of less than 1% and absence from the CISA KEV catalog suggest no widespread exploitation has been observed, yet the ease of attack qualifies it as a reasonable risk for exposed Helidon instances.
OpenCVE Enrichment