Home

Description

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

PUBLISHED Reserved 2025-07-24 | Published 2025-07-24 | Updated 2025-07-31 | Assigner OB




MEDIUM: 6.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C/CR:L/IR:L/AR:L/MAV:A/MAC:L/MPR:L/MUI:N/MS:U/MC:L/MI:L/MA:L

Problem types

CWE-668 Exposure of Resource to Wrong Sphere

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

3.2.4.x (rpm) before 3.2.4.8
affected

4.2.1 x (rpm) before 4.2.1.10
affected

4.2.x (rpm) before 4.2.5
affected

4.3.3.x (rpm) before 4.3.3.2
affected

4.3.4 (rpm)
unaffected

References

github.com/oceanbase/oceanbase/security

cve.org (CVE-2025-8107)

nvd.nist.gov (CVE-2025-8107)

Download JSON