Impact
The Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, contains a severe flaw that permits an unauthenticated attacker who can reach the service via HTTP to compromise the system. The vulnerability enables the attacker to create, delete, or modify resources, thereby exposing critical data and allowing unauthorized modification of application state. Additionally, the flaw can be used to cause partial denial of service. This is a type of Access Control weakness (CWE-284). The impact includes confidentiality, integrity, and availability, as reflected in the CVSS vector.
Affected Systems
Affected systems are limited to Oracle Helidon deployments with versions 4.0.0 through 4.4.1, as these are the only releases identified as vulnerable.
Risk and Exploitability
Risk and exploitability are high: the CVSS v3.1 score of 9.4 reflects a low attack complexity, no privileges, no user interaction, and an unmodified scope, indicating the flaw can be exploited by any networked attacker. The EPSS score of < 1% suggests a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog; the description explicitly characterizes it as easily exploitable via standard HTTP access, reinforcing the need for immediate attention.
OpenCVE Enrichment