Impact
The vulnerability in Helidon MicroProfile Security allows a low‑privileged attacker with network access via HTTP to perform unauthorized updates, inserts, or deletes on data exposed by Helidon, and to read a subset of that data. The flaw arises from improper authorization controls in the Helidon MicroProfile Security component, leading to confidentiality and integrity impacts as reflected in the CVSS vector. Availability remains unaffected.
Affected Systems
Oracle Helidon versions 4.0.0 through 4.5.4 are affected. These are part of Oracle Fusion Middleware and are deployed in environments that expose HTTP endpoints for Helidon services.
Risk and Exploitability
The CVSS base score of 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) indicates moderate risk. The EPSS score of less than 1% signals a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers only need network connectivity to a Helidon HTTP interface; no local privilege or user interaction is required beyond a low privileged user context. The exploit is considered easily exploitable based on vendor characterization.
OpenCVE Enrichment