Impact
Vulnerability in the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, allows a low‑privileged attacker with network access via HTTP to compromise the affected versions (4.0.0-4.4.1). Successful exploitation enables unauthorized update, insert or delete access to some Helidon‑accessible data and unauthorized read access to a subset of Helidon‑accessible data. This impacts confidentiality and integrity of data exposed through Helidon.
Affected Systems
Helidon versions 4.0.0 through 4.4.1, part of Oracle Fusion Middleware's Imperative Web Server component, are affected by this vulnerability. The component in question is included in Oracle's Helidon product line.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate risk, with an AV:N and low privilege required (PR:L) but no user interface requirement. EPSS score of < 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers need only HTTP network access to a Helidon instance and can exploit the flaw to gain unauthorized read and write capabilities to a subset of the server’s data.
OpenCVE Enrichment