Impact
A missing authorization flaw (CWE-284) in Oracle Helidon’s Imperative Web Server permits an unauthenticated attacker to send a crafted HTTP request and gain the ability to run arbitrary code. The vulnerability arises from improper access control checks on HTTP endpoints, allowing remote code execution without credentials. Consequences include full compromise of the Helidon service, exposing all data and services it handles, and potentially a pivot to other network resources.
Affected Systems
Helidon versions 4.0.0 through 4.4.1 are vulnerable. The issue exists in the Imperative Web Server component of these releases. The latest release, 4.5.0, includes the necessary fix and should be adopted if available.
Risk and Exploitability
The EPSS score is below 1 %, indicating the attack likelihood is presently very low, yet the CVSS 3.1 base score of 9.8 highlights the catastrophic impact of a successful exploit. The flaw is easily triggered remotely via a simple HTTP request, requiring no authentication. The vulnerability is not listed in the CISA KEV catalog, but its severity warrants immediate attention to prevent potential compromise.
OpenCVE Enrichment