In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22483 | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/oceanbase/oceanbase/security |
|
History
Thu, 24 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. | |
| Weaknesses | CWE-269 CWE-668 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OB
Published:
Updated: 2025-07-31T09:10:09.184Z
Reserved: 2025-07-24T07:08:14.587Z
Link: CVE-2025-8107
Updated: 2025-07-24T13:17:15.353Z
Status : Deferred
Published: 2025-07-24T08:15:31.037
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8107
No data.
OpenCVE Enrichment
No data.
EUVD