Impact
The Helidon product of Oracle Fusion Middleware includes a vulnerability in its Imperative Web Server component. The affected releases are 4.0.0 through 4.4.1. An unauthenticated attacker who can reach the server over HTTP can exploit the flaw, creating, deleting, or modifying critical data and gaining full access to all data exposed by Helidon. This results in a loss of confidentiality and integrity for the data served by the application. The flaw is an access‑control weakness (CWE‑284).
Affected Systems
Helidon versions 4.0.0 to 4.4.1 of Oracle Fusion Middleware are affected. Any deployment that exposes its HTTP endpoints to external network traffic is vulnerable. Earlier or later releases, including 4.5.0, are not impacted by this flaw.
Risk and Exploitability
The CVSS base score of 9.1 marks the vulnerability as critical. Because exploitation requires only a network‑reachable HTTP connection with no authentication, the attack vector is straightforward. The EPSS figure of less than 1% indicates that, to date, it is unlikely to be widely exploited in the wild; the vulnerability is also not included in the CISA KEV catalog. Nonetheless, due to its severe impact and the ease of exploitation, any exposed Helidon instance should be patched immediately.
OpenCVE Enrichment