Impact
The flaw resides in the Imperative Web Server component of Oracle Helidon. Supported versions 4.0.0 to 4.5.2 are vulnerable. An unauthenticated attacker with network access via HTTP can add, modify, or delete data, read a subset of protected data, and induce a partial denial of service. This occurs due to missing or incorrect access‑control checks, classified as CWE‑284.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.2 are affected. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS v3.1 Base Score of 7.3 reflects moderate confidentiality, integrity, and availability impacts with low attack complexity and zero required privileges. The EPSS score, being less than 1 %, suggests a low probability of exploitation in the wild, yet the requirement for only HTTP network access and absence of authentication makes the vulnerability remotely exploitable from any external network. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at this time.
OpenCVE Enrichment