Impact
Oracle Helidon versions 1.0.0 through 1.4.18 contain a vulnerability in the Imperative Web Server component that allows an unauthenticated attacker to perform actions over HTTP that lead to creation, deletion, or modification of critical data, as well as read access to subsets of data. The weakness permits the attacker to gain control over Helidon‑managed resources without any authentication, thereby compromising the confidentiality and integrity of data maintained by the system.
Affected Systems
The affected product is Oracle Helidon, a component of Oracle Fusion Middleware. Versions 1.0.0 through 1.4.18 are known to be vulnerable; newer releases are not impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 reflects a high impact vulnerability with low attack complexity and no required privileges. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the ease of exploitation with only network access via HTTP points to a high threat level. The vulnerability is not listed in the CISA KEV catalog, yet the combination of unauthenticated access and severe data‑manipulation potential demands immediate attention. Attackers with network visibility can send crafted HTTP requests to the Helidon server to trigger the flaw, gaining full control over data operations.
OpenCVE Enrichment