Impact
An unauthenticated attacker who can reach Oracle Helidon over HTTP can perform unauthorized updates, inserts, or deletions of protected data, read a subset of information that should not be exposed, and trigger a partial denial of service. Supported Helidon versions 4.0.0 through 4.4.1 are affected. The vulnerability has a CVSS 3.1 Base Score of 7.3, indicating moderate impacts on confidentiality, integrity, and availability, and stems from a lack of proper access control enforcement (CWE‑284).
Affected Systems
Oracle Helidon versions 4.0.0 through 4.4.1 are affected. No other products are identified in the supplied data.
Risk and Exploitability
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) shows that the attacker needs only network connectivity and no credentials or user interaction to succeed. The EPSS score of < 1% indicates a very low exploitation probability, yet the lack of an authentication requirement suggests that compromising Helidon can still be achievable in environments that expose it to external traffic. The vulnerability is not currently listed in CISA’s KEV catalog, meaning no widespread exploitation has been reported. Nonetheless, the potential for data loss, unauthorized manipulation, and service interruption warrants prompt remediation.
OpenCVE Enrichment