Impact
The vulnerability in Oracle Helidon permits an unauthenticated attacker who can reach the HTTP endpoint to read, insert, update, or delete Helidon data, resulting in loss of confidentiality and integrity for those data sets. Based on the description, the root cause involves insufficient access controls and lack of authentication in the Imperative Web Server component.
Affected Systems
Affected systems are deployments of Oracle Helidon versions 4.0.0 through 4.4.1 running as part of Oracle Fusion Middleware, specifically those exposing the Imperative Web Server HTTP interface.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity with low confidentiality and integrity impact and no availability impact. The EPSS score of <1 % shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is a network-based HTTP access that can be exercised by any external user contacting the Helidon HTTP endpoint, which is a realistic network-based attack surface.
OpenCVE Enrichment