Impact
The LRA component of Oracle Helidon is vulnerable to a credential‑less authorization bypass (CWE‑284) that permits an unauthenticated attacker to modify, insert, or delete data via HTTP endpoints. Because no credentials are required, the attacker can target exposed endpoints and achieve the specified impacts. The flaw has a CVSS v3.1 base score of 6.5.
Affected Systems
Oracle Helidon versions 4.0.0-4.5.4, and the vulnerability applies to any deployment that has LRA enabled and publicly reachable over the network.
Risk and Exploitability
The EPSS score of less than 1 % indicates a low expected exploitation vulnerability remains fully exploitable without authentication over a common network protocol. The flaw is not listed in CISA’s KEV catalog. Attackers can trigger the issue by sending crafted HTTP requests to the Helidon endpoint from any host with network connectivity, making the risk significant for publicly exposed instances. Given the CVSS score and the lack of mitigating controls in affected versions, applying the vendor’s patch should be prioritized.
OpenCVE Enrichment