Impact
A vulnerability in Oracle Helidon's Imperative Web Server, affecting versions 3.0.0 through 3.2.17, allows an unauthenticated attacker with network access via HTTP to compromise Helidon, enabling unauthorized access to all data the server exposes. This results in a high confidentiality impact and potential exposure of critical data.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17, specifically the Imperative Web Server component, are affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 highlights a medium‑high risk to confidentiality. The EPSS metric indicates a very low exploitation probability (< 1 %). The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by issuing unauthenticated HTTP requests to the Helidon service from any host that can reach it over the network; no credentials or special privileges are required.
OpenCVE Enrichment