Impact
Helidon contains an unauthenticated HTTP access control weakness that allows a network‑connected attacker to update, insert, delete, or read some Helidon data and cause a partial denial of service. This flaw results from missing authorization checks in the Imperative Web Server component and is classified as an Access Control weakness (CWE‑284). The impact includes confidentiality, integrity, and availability compromise, potentially corrupting data and disrupting service.
Affected Systems
The affected product is Oracle Helidon versions 4.0.0-4.4.1. No other releases are reported as vulnerable. Operators should confirm they are running one of these releases and that a newer patch has not already been applied.
Risk and Exploitability
The CVSS 3.1 base score of 7.3 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely over HTTP from any host that can reach the Helidon instance without authentication.
OpenCVE Enrichment