Impact
A vulnerability in Oracle Helidon’s Imperative Web Server allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can cause the server to hang or crash repeatedly, resulting in a full denial of service.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. The vulnerability resides in the Imperative Web Server component that handles HTTP requests within the Fusion Middleware stack.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is < 1%, showing a low likelihood of exploitation. Because the attack requires no authentication or privileges, a remote attacker can still target the system. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment