We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-8107



Description

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

Reserved 2025-07-24 | Published 2025-07-24 | Updated 2025-07-25 | Assigner OB


MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C/CR:L/IR:L/AR:L/MAV:A/MAC:L/MPR:L/MUI:N/MS:U/MC:L/MI:L/MA:L

Problem types

CWE-668 Exposure of Resource to Wrong Sphere

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

3.2.4.x before 3.2.4.9
affected

4.2.1 x before 4.2.1.10
affected

4.2.x before 4.2.5
affected

4.3.3.x before 4.3.3.2
affected

4.3.4
unaffected

References

github.com/oceanbase/oceanbase/security

cve.org (CVE-2025-8107)

nvd.nist.gov (CVE-2025-8107)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-8107

Support options

Helpdesk Chat, Email, Knowledgebase