Impact
A vulnerability in the Helidon Imperative Web Server component of Oracle Fusion Middleware allows a low‑privileged attacker with network access via HTTP to perform unauthorized update, insert, delete, or read operations on data exposed by the application. The flaw is a result of missing or weak access control. Successful exploitation can lead to both confidentiality and integrity impacts, as reflected in the CVSS score of 5.4.
Affected Systems
The vulnerability affects Oracle Helidon versions from 3.0.0 through 3.2.17. No other products or versions are listed as impacted by the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate risk to confidentiality and integrity. Because the flaw can be triggered remotely over untrusted networks without user interaction, the EPSS score is below 1%, indicating a very low but non‑zero likelihood of exploitation. The flaw is not identified as a Known Exploited Vulnerability by CISA, but organizations running Oracle Helidon versions 3.0.0 through 3.2.17 should assess the exposure and consider immediate mitigation.
OpenCVE Enrichment