Impact
Oracle Helidon’s Imperative Web Server contains an improper access control flaw that allows unauthenticated HTTP requests to update, insert or delete data and to read restricted data. The vulnerability, classified as CWE‑284, compromises confidentiality and integrity of Helidon‑accessible information. With a CVSS 3.1 base score of 4.8, it poses a moderate risk but is still a serious issue that can lead to unauthorized data changes and disclosures.
Affected Systems
The flaw affects Oracle Helidon versions 4.0.0 through 4.5.0, specifically the Imperative Web Server component. No other supported Helidon releases are listed as impacted.
Risk and Exploitability
An attacker can exploit the issue from any network location that can reach Helidon over HTTP, without requiring authentication or user interaction. The EPSS score of <1% indicates a very low probability of exploitation, while the CVSS score of 4.8 reflects moderate risk. Because the vulnerability is not listed in the CISA KEV catalog and no public exploits have been documented, the likelihood of exploitation remains uncertain, though the ease of network access could increase potential abuse.
OpenCVE Enrichment