Impact
The Helidon product of Oracle Fusion Middleware contains a flaw in the Imperative Web Server. Versions 4.0.0 through 4.5.2 are affected. An unauthenticated attacker with network access via HTTP can exploit the vulnerability to cause a partial denial of service. The vulnerability is an access control weakness classified as CWE-284, allowing requests to overload or destabilize the server without compromising confidentiality or integrity.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.2 are affected by this vulnerability. The flaw resides in the Imperative Web Server component and can be triggered by any HTTP request. No other Oracle Fusion Middleware products or components are listed as impacted.
Risk and Exploitability
The CVSS Base Score of 5.3 indicates moderate risk for availability. The EPSS score is under 1 % and the vulnerability is not listed in the CISA KEV catalog, signifying a low probability of widespread exploitation. The likely attack vector is network‑based HTTP traffic; an unauthenticated attacker with network access can trigger this DoS by sending malicious requests over a standard web port.
OpenCVE Enrichment