Impact
The flaw in Helidon’s Imperative Web Server allows any unauthenticated attacker with network access over HTTP to trigger a server hang or repeated crash, causing a total loss of service availability. Helidon versions 3.0.0 through 3.2.18 are affected; version 3.2.19 includes the fix. The vulnerability does not compromise confidentiality or integrity, but the impact on availability is severe as described by the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The underlying weakness involves improper access control, as indicated by CWE-284.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.18 are affected; the fixed release 3.2.19 is not vulnerable. Helidon is part of Oracle Fusion Middleware and is distributed under the Oracle Corporation brand.
Risk and Exploitability
The CVSS base score of 7.5 places the vulnerability in the medium-to-severity range, while an EPSS score of < 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can simply send crafted HTTP requests from any remote system with network connectivity to a publicly exposed Helidon instance, and no authentication or privileged access is required. Because the attack is straightforward, the risk to environments with exposed Helidon instances remains significant despite the low EPSS.
OpenCVE Enrichment