Impact
Oracle Helidon 4.0.0-4.4.1 contains an access-control flaw that permits unauthenticated HTTP requests to retrieve a restricted subset of data, compromising confidentiality. The weakness is due to improper permissions enforcement (CWE-284) in the imperative web server component. Successful exploitation can expose sensitive information but does not alter data integrity or disrupt availability.
Affected Systems
The affected product is Oracle Helidon, versions 4.0.0 through 4.4.1. The vulnerability is present in the imperative web server component, which processes normal HTTP traffic. No earlier or later releases outside this range remain susceptible according to the vendor’s advisory.
Risk and Exploitability
The public CVSS v3.1 base score is 5.3, reflecting moderate severity with a confidentiality impact. The EPSS score is less than 1%, indicating a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attacks require only network access to Helidon over HTTP, no authentication, and no privilege escalation. The likely attack vector is an unauthenticated remote attacker sending crafted HTTP requests to a publicly reachable Helidon instance.
OpenCVE Enrichment