Impact
The Helidon Imperative Web Server of Oracle Fusion Middleware contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Helidon. The flaw enables unauthorized creation, deletion, or modification of data, or complete access to all Helidon‑accessible data. The CVSS 3.1 Base Score of 9.1 reflects significant confidentiality and integrity impacts, with an exploit that requires no authentication, minimal attack effort, and no user interaction.
Affected Systems
Oracle Helidon product of Oracle Fusion Middleware, versions 1.0.0 through 1.4.18, is affected. The vulnerability resides in the Imperative Web Server component and is present in those releases.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity, high‑impact vulnerability that can be exploited remotely over HTTP. The EPSS score of < 1% indicates a very low exploitation probability, but the ease of exploitation and lack of required credentials mean the risk remains high. The attack vector is most likely through ordinary network traffic targeting the Helidon HTTP interface, where an unauthenticated attacker can manipulate or retrieve critical data.
OpenCVE Enrichment