Impact
A vulnerability has been identified in the Helidon product of Oracle Fusion Middleware, specifically within the Imperative Web Server component. The flaw allows an unauthenticated attacker with network access via HTTP/2 to read certain data that should be protected and to trigger a partial denial of service. This weakness is a CWE-284 Access Control Weakness. The vulnerability affects Helidon versions 4.0.0 through 4.4.1. Successful attacks can lead to unauthorized disclosure of a subset of Helidon‐accessible data and can disrupt service availability, as reflected in the CVSS score of 6.5.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. No Helidon releases beyond 4.4.1 are listed as impacted in the advisory. Systems running these versions should evaluate whether they expose the Imperative Web Server over HTTP/2 and assess risk accordingly.
Risk and Exploitability
The vulnerability can be exploited without authentication or specialized privileges. The attacker simply sends crafted HTTP/2 traffic to the target host. Based on the description, it is inferred that the attack requires no user interaction or configuration changes beyond network access. The CVSS base score of 6.5 indicates low confidentiality impact and low availability impact. The EPSS score of < 1 % suggests a very low probability of exploitation. Oracle Helidon versions 4.0.0‑4.4.1 are affected. The flaw is not listed in the CISA KEV catalog, indicating limited public exploitation at this time. However, the ability to cause data leakage and partial service disruption warrants timely remediation.
OpenCVE Enrichment