Impact
Oracle Helidon 4.0.0-4.4.1 has an improper access control flaw in its Imperative Web Server component that allows an attacker with low privilege and network access over HTTP to perform unauthorized update, insert, delete, and read operations on data that the attacker should not be able to see or modify. The vulnerability, identified as CWE-284, results in confidentiality and integrity impacts, reflected in a CVSS 3.1 base score of 5.4.
Affected Systems
The flaw affects Helidon versions 4.0.0 through 4.4.1; no other releases or Oracle products are listed as impacted.
Risk and Exploitability
With a CVSS score of 5.4 the risk is moderate, and the EPSS score of < 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Attackers can exploit the flaw over HTTP using a low‑privileged client, leveraging insufficient authorization checks to gain unauthorized data access.
OpenCVE Enrichment