Impact
The vulnerability resides in Oracle Helidon versions 3.0.0 through 3.2.17, specifically the Imperative Web Server component of the Oracle‑Fusion Middleware stack. An unauthenticated attacker who can reach the server over HTTP can read a limited set of data that should be protected, resulting in a confidentiality breach but not affecting integrity or availability. The weakness is a data exposure flaw combined with insufficient access control, classified as CWE‑284.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. Any deployment that uses any of these releases and accepts inbound HTTP traffic is susceptible; versions 3.2.18 and later are considered not affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 indicates moderate severity focused on confidentiality. The vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) confirms the vulnerability can be exploited remotely over the public HTTP interface without authentication and with minimal effort. The EPSS score of < 1 % reflects an extremely low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely leveraged by adversaries yet. Nonetheless, because the exposed surface is a public HTTP endpoint and no credentials are required, the risk to exposed services remains non‑negligible.
OpenCVE Enrichment