Impact
The Helidon product suffers from an unauthenticated HTTP vulnerability that stems from improper authentication and access control weakness (CWE-284). Affected versions are 1.0.0 through 1.4.19. An attacker can exploit this flaw to execute arbitrary code on the server, compromising confidentiality, integrity, and availability of the Helidon instance and potentially gaining full system control.
Affected Systems
Oracle Helidon versions 1.0.0 through 1.4.19 are affected. Users running any of these releases may be compromised without additional security controls.
Risk and Exploitability
The vulnerability is easily exploitable over the network, requiring only an unauthenticated HTTP connection. The CVSS score of 9.8 indicates a high risk, and the EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. The lack of KEV listing does not reduce the need for prompt action.
OpenCVE Enrichment