Impact
Vulnerability in the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, allows an unauthenticated attacker with network access via HTTP to compromise Helidon. The flaw, present in versions 4.0.0 through 4.5.2, can be exploited to perform unauthorized updates, inserts, deletes, and reads of Helidon data, as well as to trigger a partial denial of service. The weakness is due to improper access control (CWE‑284).
Affected Systems
Affected systems include Oracle Helidon versions 4.0.0 through 4.5.2, which are part of Oracle Fusion Middleware. Any deployment using these versions across enterprises that utilize Helidon for web services is at risk.
Risk and Exploitability
The CVSS v3.1 base score of 8.3 indicates a high severity, while the EPSS score is <1%. The vulnerability is not listed in the CISA KEV catalog yet. Attackers can exploit the flaw without authentication and only require standard HTTP network access; however, the EPSS score indicates a low likelihood of exploitation. The known scope change may also affect additional Oracle products, heightening the overall risk.
OpenCVE Enrichment