Impact
The Helidon WebSocket component in Oracle Fusion Middleware contains a flaw that permits an unauthenticated attacker with network access via HTTP to crash the Helidon application. The vulnerability is rooted in a weakness described by CWE-400, leading to significant disruption without compromising confidentiality or integrity.
Affected Systems
Oracle Helidon product versions 4.0.0 through 4.5.4 are affected. These versions are part of Oracle Fusion Middleware.
Risk and Exploitability
The EPSS score of under 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV. With a CVSS base score of 7.5, the flaw is considered high severity, primarily affecting availability. Unauthenticated attackers can reach the target over standard HTTP, making it potentially exploitable in environments with exposed Helidon services.
OpenCVE Enrichment