Impact
Vulnerability in Oracle Helidon's helidon-dbclient-mongodb component allows an unauthenticated attacker with network access via HTTP to obtain unauthorized read access to critical data, as well as write access that could insert, update, or delete Helidon-accessible data. The flaw also permits an attacker to trigger a partial denial of service. The base CVSS score of 7.0 reflects significant confidentiality and integrity impact. The vulnerability is difficult to exploit but exists in the public exposure of Helidon applications.
Affected Systems
Oracle Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4 are affected. The vulnerability resides in the helidon-dbclient-mongodb component, which interfaces with MongoDB databases over HTTP. Any Oracle Helidon deployment that exposes this component without authentication is susceptible.
Risk and Exploitability
With a CVSS 3.1 Base Score of 7.0, the risk is considered high. The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, suggesting no confirmed exploits but a potential for future attacks. The likely attack vector is raw HTTP traffic to the Helidon service, and an attacker would need network connectivity to the exposed endpoint. Because the vulnerability requires no credentials, it is considered a high-impact unauthenticated attack.
OpenCVE Enrichment