Impact
The Helidon product of Oracle Fusion Middleware, specifically its Imperative Web Server component, contains a flaw that permits unauthenticated attackers with network access to send HTTP requests that expose confidential data. The vulnerability is easily exploitable and can lead to full access to all Helidon‑served data, posing a significant confidentiality risk.
Affected Systems
The affected product is Oracle Helidon, versions 4.0.0 through 4.4.1. The flaw resides in the web server layer that handles inbound HTTP traffic within the Oracle Fusion Middleware stack.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a high risk condition. The vector states that a network attacker can exploit the flaw without authentication, so the potential for exploitation is substantial. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers could read any data exposed through Helidon, making prompt remediation essential.
OpenCVE Enrichment