Impact
The vulnerability in Oracle Helidon versions 4.0.0 through 4.4.1 is a CWE‑284 Improper Access Control flaw that permits an unauthenticated attacker to reach the application over HTTP and obtain confidential data or full access to all Helidon‑accessible resources. The flaw is classified as a confidentiality‑impact issue with a CVSS 3.1 score of 7.5 and a vector indicating a network attack, low complexity, no required privileges, no user interaction, and only confidentiality impact.
Affected Systems
Affected systems include Oracle Helidon versions 4.0.0 through 4.4.1, which form part of Oracle Fusion Middleware's Imperative Web Server component. Helidon is deployed in enterprise web applications that rely on its HTTP server capabilities.
Risk and Exploitability
The risk is significant because the flaw can be exploited without authentication or user interaction, resulting in substantial confidentiality loss. The EPSS score of < 1% indicates a very low probability of exploitation, yet the high confidentiality impact means that even a single successful attack can expose critical data. The vulnerability is not listed in CISA's KEV catalog. Attackers can target the service from any network that can reach the Helidon HTTP port, making the vector a straightforward network‑based attack such as exploiting an open HTTP endpoint.
OpenCVE Enrichment