Impact
The Helidon Imperative Web Server contains an access control flaw that lets an unauthenticated attacker issuing HTTP requests change or read Helidon‑accessible data that is not intended for public exposure. The vulnerability affects versions 4.0.0 through 4.4.1 and allows updates, inserts, or deletions as well as unauthorized read access to some data.
Affected Systems
Oracle Helidon versions 4.0.0‑4.4.1 are affected, specifically the Imperative Web Server component. No other Oracle products or Helidon releases are listed as impacted by the CNA.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate‑to‑high severity with confidentiality and integrity effects. The EPSS score is less than 1 %, implying a very low likelihood of exploitation currently. The vulnerability can be triggered by any unauthenticated actor with network access to the Helidon HTTP interface, without requiring credentials or elevated privileges. Although the flaw is not listed in CISA KEV, the ability to alter and expose data justifies vigilance for organizations running Helidon 4.0.0‑4.4.1.
OpenCVE Enrichment