Impact
The Helidon 3.0.0‑3.2.18 versions include a vulnerability in the Imperative Web Server that exposes a HTTP endpoint that an unauthenticated attacker can reach over the network. The weakness is a missing authorization (CWE‑284). Exploitation requires a crafted HTTP request and is described as difficult, but once achieved it allows the attacker to read critical or all data served by Helidon. The vulnerability is rated with a CVSS 3.1 Base Score of 5.9 and impacts confidentiality while leaving integrity and availability unchanged.
Affected Systems
Helidon versions 3.0.0‑3.2.18 from Oracle Corporation are vulnerable based on the advisories.
Risk and Exploitability
The CVSS score indicates moderate risk. The EPSS score of less than 1 % suggests exploitation is unlikely but still possible, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request sent to Helidon’s Imperative Web Server. Successful exploitation requires an authenticated‑free, crafted HTTP request, making it difficult yet feasible for an attacker with network access.
OpenCVE Enrichment