Impact
Oracle Helidon versions 4.0.0‑4.5.2 contain a flaw in the Imperative Web Server that permits an unauthenticated attacker with network access to the HTTP interface to modify, read, or delete data exposed by the service and to trigger a partial denial of service. The vulnerability, which has a very low EPSS score but an 8.3 CVSS base score, also carries a scope change that may affect other Oracle products that depend on the Helidon engine. These capabilities compromise confidentiality, integrity, and availability for users of the affected Helidon deployments.
Affected Systems
Helidon versions 4.0.0 through 4.5.2, released by Oracle Corporation.
Risk and Exploitability
This flaw is scored 8.3 on CVSS v3.1 with an attack vector of network and no authentication required. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The vulnerability’s scope change indicates that it may also pose a threat to additional Oracle products. Based on the description, it is likely exploitable by any entity that can reach the Helidon HTTP endpoint, making the risk high for exposed systems. No known mitigations outside of applying the vendor patch are mentioned in the advisory.
OpenCVE Enrichment