Impact
Oracle Helidon’s Imperative Web Server contains an improper access control flaw that allows an unauthenticated attacker who can reach the service over HTTP to compromise the application. By exploiting the flaw the attacker can create, delete or modify data, read a subset of data, and cause a partial denial of service. This unauthorized access is possible without authentication or user interaction, and the flaw can also affect other related products because it changes the scope of the compromise. The issue is classified as CWE-284.
Affected Systems
Oracle Helidon releases from version 3.0.0 through 3.2.19 and 4.0.0 through 4.5.2 are affected by this vulnerability. The product is part of Oracle Fusion Middleware and the flaw is located in the Helidon Imperative Web Server component.
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates a critical severity, with no authentication or user interaction required. An attacker only needs network access to a host that can reach Helidon via HTTP to exploit the flaw, making the risk high for environments that expose the service to external networks. The EPSS score of less than 1% suggests a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Because the weakness is an access control issue, exploitation can lead to unauthorized data manipulation and partial denial of service, with a scope change that may impact additional related products.
OpenCVE Enrichment