Impact
Oracle Helidon 4.0.0 through 4.5.0 contains an insecure access‑control flaw in its Imperative Web Server component. An unauthenticated attacker reaching the application via HTTP may compromise Helidon and read a subset of the data exposed by the service. The vulnerability leads to a confidentiality impact with a CVSS v3.1 base score of 5.3, reflecting that it is easily exploitable but does not compromise integrity or availability. The weakness aligns with CWE‑284, which describes improper access control.
Affected Systems
Oracle Helidon 4.0.0–4.5.0, part of Oracle Fusion Middleware's Imperative Web Server component, is the affected system. No other versions or products are listed as impacted in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. An unauthenticated attacker can trigger the flaw over the network via HTTP, requiring no privileged credentials or special configuration, thus providing a straightforward potential vector for data leakage.
OpenCVE Enrichment