Impact
Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, is vulnerable to a network‑based, unauthenticated attack over HTTP. Supported versions 4.0.0 through 4.4.1 can be compromised, allowing an attacker to read, insert, update, or delete Helidon‑managed data, thereby affecting confidentiality and integrity.
Affected Systems
The only systems explicitly listed as affected are Oracle’s Helidon versions 4.0.0 through 4.4.1 installed under the Fusion Middleware stack, specifically the Imperative Web Server component. No other product versions are mentioned, but the description notes that attacks may have a broader impact if other Oracle products rely on Helidon, potentially expanding the vulnerability’s scope beyond Helidon alone.
Risk and Exploitability
With the CVSS score of 7.2, the vulnerability is classified as medium to high severity. The EPSS score indicates a very low exploitation probability (<1%), meaning that while the exploit is theoretically possible, it is unlikely to be widely used. Because the flaw is exploitable without authentication and requires only standard HTTP traffic, network‑connected attackers can launch attacks against exposed Helidon endpoints. The vulnerability is not listed in the CISA KEV catalog at this time; however, the simplicity of the exploitation path and significant impact warrant treating the risk as high.
OpenCVE Enrichment