Impact
The vulnerability affects Oracle Helidon’s Imperative Web Server component and permits an unauthenticated attacker with network HTTP access to update, insert, or delete Helidon‑accessible data or read a subset of that data. The flaw is an Improper Privilege Management issue (CWE‑284) that degrades confidentiality and integrity. The available CVSS 3.1 base score of 7.2 reflects these impacts, and the vulnerability’s scope change indicates that compromise may extend beyond Helidon to other Oracle products.
Affected Systems
Affected systems are Oracle Helidon versions 4.0.0 through 4.5.2; the CPE list also includes 4.5.3, which may be impacted until further clarification. The flaw specifically targets the web server functionality of Helidon.
Risk and Exploitability
Risk is moderate to high with a CVSS base score of 7.2, an EPSS score of less than 1%, and not listed in KEV; exploitation requires no authentication, a direct HTTP connection, and carries a low probability of success, so immediate attention is advised.
OpenCVE Enrichment