Impact
The vulnerability is an unauthorized HTTP endpoint in Oracle Helidon’s Imperative Web Server that allows an attacker to create, delete, or modify critical data without authentication. The flaw enables the attacker to bypass existing access controls and alter or destroy data that should be protected, causing both confidentiality and integrity loss for any data accessed through the Helidon instance. The weakness is classified as CWE‑284: Improper Access Control.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The product is Oracle’s Helidon web server component, available within Oracle Fusion Middleware and sold separately. No other vendors or products are listed as affected in the CNA data.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 comes from a network attacker (AV:N) with low complexity (AC:L) and no privileges (PR:N) exploiting an unauthenticated HTTP request. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low but nonzero probability of exploitation. The likelihood of successful attack is contingent on the target having the vulnerable endpoint exposed to the public or an untrusted network.
OpenCVE Enrichment