6.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Description
In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
Basic Information
ID
CVE-2025-8107
Source
OB
Published
Jul 24, 2025 at 07:12
Modified
Jul 31, 2025 at 09:10
Affected Product
Vendor
OB
Product
OceanBase Server
Version
3.2.4.x
Affected Versions
OB OceanBase Server 3.2.4.x
OB OceanBase Server 4.2.1 x
OB OceanBase Server 4.2.x
OB OceanBase Server 4.3.3.x
OB OceanBase Server 4.2.1 x
OB OceanBase Server 4.2.x
OB OceanBase Server 4.3.3.x