Impact
An attacker with network access to the Helidon Imperative Web Server can make HTTP requests without authentication to breach the system. The vulnerability allows the attacker to gain unauthorized read access to all data exposed by Helidon, potentially exposing sensitive information. The security impact is limited to confidentiality and does not directly affect integrity or availability.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. The product is part of Oracle Fusion Middleware and operates as the Imperative Web Server component.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a moderate to high severity. Explanations for the exploitation expose the lack of authentication for HTTP communication. Because the EPSS score is reported as <1%, the likelihood of exploitation is considered low, but the vulnerability is not listed in the CISA KEV catalog. Given the network‑exposed attack vector, it can be reasonably inferred that a remote attacker could exploit this flaw by sending crafted HTTP requests to a Helidon instance without requiring credentials.
OpenCVE Enrichment