Impact
A vulnerability in the Helidon Imperative Web Server allows attackers to perform unauthorized update, insert, delete, or read operations on data exposed by Helidon. The flaw, identified as an access control weakness, is exploitable without authentication over the network, leading to confidentiality and integrity compromise as reflected by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N. Note: The official description was updated; the core details remain consistent with the prior assessment.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected by this vulnerability. The flaw is confined to Helidon but can affect other products that rely on it because of a scope change.
Risk and Exploitability
The CVSS score of 7.2 reflects moderate to high severity, the EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack path requires only HTTP network access to the Helidon service, enabling an unauthenticated attacker to manipulate or read protected data. Given the lack of defensive controls reported, the risk of exploitation remains significant.
OpenCVE Enrichment