Impact
Helidon, part of Oracle Fusion Middleware, contains an Imperative Web Server component that in versions 4.0.0 through 4.4.1 has an access control weakness. The vulnerability allows a low‑privileged attacker with network access via HTTP to perform unauthorized updates, inserts, deletes, and read operations on data exposed by Helidon. The CVE assigns a CVSS 3.1 score of 5.4, indicating low confidentiality and integrity impact while availability remains unaffected.
Affected Systems
The affected systems are Oracle Helidon 4.0.0 through 4.4.1, part of Oracle Fusion Middleware. No other product versions or variants are listed as impacted.
Risk and Exploitability
The CVE states the vulnerability is easily exploitable and requires only low privilege and standard HTTP network access. The CVSS 3.1 Base Score of 5.4 indicates medium‑level confidentiality and integrity impact while availability remains unchanged. No code execution or availability impact is reported. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Deployments exposing Helidon to untrusted networks could face elevated risk because the attack vector is purely network‑based and does not require authentication.
OpenCVE Enrichment