In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/oceanbase/oceanbase/security |
![]() ![]() |
History
Thu, 24 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Jul 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. | |
Weaknesses | CWE-269 CWE-668 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: OB
Published: 2025-07-24T07:12:13.878Z
Updated: 2025-07-31T09:10:09.184Z
Reserved: 2025-07-24T07:08:14.587Z
Link: CVE-2025-8107

Updated: 2025-07-24T13:17:15.353Z

Status : Awaiting Analysis
Published: 2025-07-24T08:15:31.037
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-8107

No data.