Impact
Oracle Helidon product (versions 4.0.0 through 4.5.0), the Imperative Web Server component of Oracle Fusion Middleware, contains a flaw in its access control that permits an unauthenticated attacker with network access via HTTP to force the server to either hang or crash. The vulnerability’s impact is limited to availability, as the CVSS v3.1 Base Score of 7.5 reflects a high availability effect with no impact on confidentiality or integrity.
Affected Systems
Supported Oracle Helidon versions that are impacted are 4.0.0 through 4.5.0, as indicated in the advisory. No other Helidon releases are listed as vulnerable.
Risk and Exploitability
Exploitation is possible from any remote host that can reach the Helidon server over HTTP. No user interaction or authentication is required, and the attack complexity is low. The EPSS score of less than 1% indicates a very low current probability of exploitation, and the vulnerability is not catalogued in CISA’s KEV. Nevertheless, a successful attack would immediately halt the Helidon service, causing a denial of service for all dependent applications.
OpenCVE Enrichment