Impact
A flaw in Oracle Helidon’s Imperative Web Server permits an attacker who can reach the service over HTTP to create, delete, or modify data without authentication. The vulnerability does not affect availability or confidentiality, but it gives full control over any data the server manages, while an attacker does not need prior credentials. The weakness is tied to improper access control mechanisms, allowing a network attacker to write or remove data that should be protected.
Affected Systems
Oracle Corporation Helidon 4.0.0-4.5.0 are affected. No other versions, patches, or products are listed in the CNA data.
Risk and Exploitability
With a CVSS 3.1 base score of 7.5 the flaw presents a high‑severity risk. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTP and requires no authentication, making exploitation straightforward for any external actor who can reach the Helidon instance. Successful exploitation grants the attacker arbitrary data modification, potentially affecting critical business processes.
OpenCVE Enrichment