First published: Tue Apr 19 2022(Updated: )
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions that are affected are 1.4.10 and 2.0.0-RC1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Helidon | =1.4.10 | |
Oracle Helidon | =2.0.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21404.
The affected software is Oracle Helidon versions 1.4.10 and 2.0.0-RC1.
The severity of CVE-2022-21404 is high with a CVSS score of 8.1.
An unauthenticated attacker with network access via HTTP can exploit CVE-2022-21404.
Oracle has released a security patch to fix CVE-2022-21404. It is recommended to install the latest patch as soon as possible.