Impact
Helidon, part of Oracle Fusion Middleware, contains an issue in the Helidon‑integrations‑neo4j component that lets an unauthenticated attacker who has physical access to the hardware’s communication segment compromise the application. A successful attack permits the attacker to create, delete, or alter data that Helidon stores or accesses, leading to confidentiality and integrity loss for all Helidon‑managed data.
Affected Systems
The vulnerability affects Oracle Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4. Any deployments of these Helidon releases that use the Neo4j integration component are impacted.
Risk and Exploitability
With a CVSS 3.1 base score of 6.8, the vulnerability carries moderate severity and depends on a physical attack vector that requires high effort. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Nevertheless, because the impact includes unauthorized creation, deletion, or modification of critical data, organizations should consider this a significant risk if physical access to the environment can be achieved by malicious actors.
OpenCVE Enrichment