Impact
A flaw in Oracle Helidon’s Imperative Web Server permits an unauthenticated attacker with network access via HTTP to read a limited set of data that should be protected and trigger a partial denial of service. The weakness is an instance of Incorrect Access Control (CWE-284), exposing sensitive information and interrupting service availability.
Affected Systems
The affected product is Oracle Helidon from Oracle Corporation. Vulnerable releases include Helidon 4.0.0 through 4.4.1; Helidon 4.5.0 is not listed as vulnerable in the current description. No other components are identified as affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 reflects moderate impact on confidentiality and availability. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network-based via HTTP and requires no authentication; the attacker can simply send crafted HTTP requests to the Helidon service to read protected data and cause a partial denial of service.
OpenCVE Enrichment