Impact
Helidon 4.0.0‑4.4.1 in Oracle Fusion Middleware contains an authorization flaw in the Imperative Web Server component that allows an unauthenticated attacker with network access over HTTP to read a subset of data exposed by the application. The exploit does not require credentials, and success results in unauthorized read access to Helidon data. This vulnerability is classified as CWE‑284 and carries a moderate CVSS v3.1 base score of 5.3, indicating a confidentiality impact.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. The flaw resides in the Helidon Imperative Web Server component, which is part of Oracle Fusion Middleware. No later Helidon releases have been identified as vulnerable; the advisory does not mention versions beyond 4.4.1.
Risk and Exploitability
The CVSS v3.1 base score of 5.3 denotes a moderate severity that primarily affects confidentiality. The EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known exploitation at present. An attacker can reach the affected service via HTTP without authentication, exploiting the missing authorization checks to retrieve a subset of Helidon data. This network‑based attack can occur in any environment where Helidon is exposed to the Internet or an internal network.
OpenCVE Enrichment