Impact
This vulnerability resides in the Imperative Web Server component of Oracle Helidon. An attacker who can reach the service over HTTP need not be authenticated to issue requests that modify, insert, delete or read data that should be protected, and can also trigger a partial denial of service. The flaw represents an authorization bypass (CWE-284) and affects confidentiality, integrity, and availability at a high severity level according to the specified CVSS vector. The vulnerability affects Helidon versions 4.0.0 to 4.4.1.
Affected Systems
Oracle Helidon versions 4.0.0 to 4.4.1 are affected. The product is part of Oracle Fusion Middleware and typically runs as a web server component in enterprise Java environments.
Risk and Exploitability
The CVSS v3.1 base score of 7.3 indicates high severity. The EPSS score of < 1% shows a very low yet non-zero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Because the attack only requires unauthenticated HTTP traffic, the potential for abuse is easy to satisfy, making the risk significant if not promptly mitigated.
OpenCVE Enrichment