Impact
The Helidon product of Oracle Fusion Middleware faces a flaw in its imperative web server that allows an unauthenticated attacker with network access via HTTP/2 to cause the application to hang or crash, resulting in a complete denial of service. The vulnerability affects supported versions 3.0.0 through 3.2.18 and is rated a CVSS base score of 7.5, reflecting a high availability impact. Attackers do not need credentials or user interaction to exploit this flaw.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.18 are affected, with the flaw located in the imperative web server component of Oracle Fusion Middleware.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 emphasizes the serious availability impact achievable by an unauthenticated attacker with network access. The EPSS score of <1% indicates that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits. Nonetheless, the attack vector involves standard HTTP/2 requests that could be sent from any reachable host, making the scenario highly plausible if the attacker gains network access to the Helidon instance.
OpenCVE Enrichment