Impact
A flaw in Oracle Helidon's Imperative Web Server permits an attacker who can reach the HTTP interface to obtain unauthenticated access. The vulnerability is easily exploitable, enabling a threat actor to read any data that Helidon serves. This includes the potential for complete read access to all Helidon‑exposed data, thereby exposing critical information without authentication or special privileges.
Affected Systems
Oracle Helidon product, versions from 3.0.0 through 3.2.17, is affected. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates a high risk severity, reflecting a network attack vector, low complexity, and no user interaction requirement. The EPSS score of <1% shows a very low but non‑zero likelihood of exploitation, underscoring that the flaw remains a threat because it requires only network connectivity and no authentication. Although the vulnerability is not presently listed in the CISA KEV catalog, it can be exploited via simple HTTP requests, granting full read access to Helidon data for any host on the network.
OpenCVE Enrichment