Impact
A flaw in Oracle Helidon’s Imperative Web Server affects supported versions 4.0.0 through 4.4.1 and allows an unauthenticated attacker with network access via HTTP to modify or delete data and read a subset of Helidon accessible data. The vulnerability stems from improper access control, which permits unauthorized write or read operations against protected resources and compromises the confidentiality and integrity of data stored or served by the Helidon instance.
Affected Systems
Oracle Corporation's Helidon product, versions 4.0.0 through 4.4.1, is affected. These supported releases are deployed within Oracle Fusion Middleware environments.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate severity weakness. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. However, the attack vector is over the network via HTTP, and the vulnerability is easily exploitable by an unauthenticated user, raising the likelihood that an attacker could successfully conduct unauthorized data operations if the application remains exposed.
OpenCVE Enrichment