Impact
Helidon's Imperative Web Server contains an Improper Access Control flaw (CWE-284) that allows unauthenticated HTTP requests to trigger a hang or crash, resulting in denial of service. This vulnerability affects versions 3.0.0 through 3.2.19. The CVSS 3.1 score of 7.5 reflects the high availability impact with no confidentiality or integrity impact.
Affected Systems
The affected product is Oracle’s Helidon Web Server, part of the Helidon component of Oracle Fusion Middleware. Vulnerable versions are 3.0.0 through 3.2.19. No newer major releases are listed as affected.
Risk and Exploitability
The flaw is considered easily exploitable; the attacker only needs network access to HTTP and no credentials. The CVSS score of 7.5 indicates a high availability impact with no confidentiality or integrity impact. Because the CVSS vector indicates a network attack with no authentication and a high availability impact, the risk is significant. The EPSS score is <1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread public exploits have been reported yet, but the potential for a deterministic denial of service makes it a high‑priority issue.
OpenCVE Enrichment