Impact
Oracle Helidon, part of Oracle Fusion Middleware, contains a vulnerability in its Imperative Web Server component. The flaw exists in Helidon versions 4.0.0 through 4.4.1 and can be exploited by an unauthenticated attacker with network connectivity to the server via standard HTTP traffic. The vulnerability allows the attacker to bypass authentication entirely, enabling arbitrary code execution and full takeover of the Helidon environment. This is a CWE-284 Authorization vulnerability.
Affected Systems
Oracle Helidon product, specifically versions 4.0.0 through 4.4.1, is affected. The component involved is the Imperative Web Server.
Risk and Exploitability
Given the CVSS score of 9.8 and the lack of a required user interaction, the risk level is high. The EPSS score is < 1%, indicating a very low probability of exploitation in the general population, but the vulnerability's vector demonstrates that any machine with network access to Helidon can exercise the exploit. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no publicly known exploits at the time of this analysis. However, it remains a significant threat due to its ease of exploitation and the complete control it grants to attackers.
OpenCVE Enrichment