Impact
The vulnerability is in the Imperative Web Server component of Oracle Helidon. An attacker who can reach the Helidon HTTP endpoint can read a subset of data that should be protected. The flaw allows unauthorized data exposure without needing any credentials. Because only confidentiality is affected, no integrity or availability impact is reported.
Affected Systems
Affected by the flaw are Oracle Helidon 4.0.0 through 4.4.1 installations. The product is part of Oracle Fusion Middleware. No other versions or components are listed as vulnerable in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The attack vector is network access via HTTP; no authentication or UI is required, meaning the vulnerability is easily exploitable. The EPSS score, indicated as <1% (approximately 0.003), shows a very low but non-zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers who can reach Helidon over the network could compromise sensitive data, so the risk remains significant.
OpenCVE Enrichment