Impact
The vulnerability exists in the Imperative Web Server component of Oracle Helidon versions 4.0.0 through 4.4.1. An unauthenticated attacker with network access over HTTP may exploit a missing authorization check, allowing unauthorized update, insert, or delete operations on Helidon‑accessible data and read access to a subset of that data. Successful exploitation requires human interaction from a person other than the attacker, and the flaw can potentially impact other products due to a scope change, though it does not provide remote code execution. The resulting confidentiality and integrity impacts are reflected in the CVSS base score of 6.1.
Affected Systems
This issue affects Oracle Helidon versions 4.0.0 through 4.4.1, a component of Oracle Fusion Middleware. The product is deployed as the imperative web server and is listed in the referenced Oracle security alert. No other product versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity vulnerability. The EPSS score is <1% and the vulnerability has not been included in the CISA KEV catalog, implying no widespread exploitation to date. The description states that the vulnerability is easily exploitable via HTTP by an unauthenticated attacker, yet successful attacks require human interaction from a person other than the attacker, which reduces the practical exploitation likelihood. Although the scope change could allow impact on additional components, there is no evidence of remote code execution. Overall, the risk is higher than low‑severity patches but lower than critical issues; mitigation is advisable promptly.
OpenCVE Enrichment