Impact
The Helidon product of Oracle Fusion Middleware (component: Imperative Web Server) contains a vulnerability affecting versions 3.0.0 to 3.2.19. An unauthenticated attacker with network access via HTTP can compromise Helidon, and the associated scope change may allow similar attacks on additional products. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, presenting a high‑severity integrity violation with a CVSS v3.1 base score of 8.6.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.19 are affected. The flaw resides in Oracle’s Fusion Middleware component and, due to the reported scope change, may also affect other Helidon modules running within the same environment. No additional product variants or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.6 reflects a significant risk to data integrity, while the EPSS score of less than 1% indicates that the current probability of exploitation remains low. However, because the flaw permits unauthenticated HTTP requests without authentication or user interaction, any exposed Helidon service can be compromised immediately by sending malicious requests to permissive endpoints. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment