Impact
Vulnerability in Oracle Helidon’s Imperative Web Server component affects supported versions 4.0.0 through 4.5.0. A high‑privileged attacker who can log on to the infrastructure where Helidon runs can compromise the application. The weakness is an improper access control flaw (CWE‑284) that allows the attacker to bypass normal authorization checks and read any data exposed through Helidon, leading to a confidentiality breach.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.0, part of Oracle Fusion Middleware, are affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 score of 4.4 indicates a moderate threat, primarily due to confidentiality impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local (AV:L) and requires an attacker to possess high‑level privileges on the infrastructure hosting Helidon. Once these prerequisites are met, the attacker can obtain unrestricted access to all data available through the Helidon instance.
OpenCVE Enrichment