Impact
A remote vulnerability exists in Oracle Helidon's Imperative Web Server that permits an unauthenticated attacker to send HTTP requests and obtain sensitive data. The weakness is a lack of proper authentication, allowing the attacker to read any data served by Helidon. The impact is the loss of confidentiality, as attackers can view critical data or all data exposed by the service. The vulnerability is an instance of CWE-200.
Affected Systems
The description identifies Helidon versions 3.0.0 through 3.2.17 as affected. The vulnerability does not apply to Helidon 3.2.18.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects a high severity for confidentiality loss. The EPSS score is less than 1%, and the vulnerability is not included in CISA’s KEV catalogue. The likely attack vector is an unauthenticated attacker sending HTTP requests to Helidon’s interface; the flaw is easily exploitable from any untrusted network that can reach the service, making it a realistic threat in exposed environments.
OpenCVE Enrichment