Description
In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22483 | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. |
References
| Link | Providers |
|---|---|
| https://github.com/oceanbase/oceanbase/security |
|
History
Thu, 24 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. | |
| Weaknesses | CWE-269 CWE-668 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: OB
Published:
Updated: 2025-07-31T09:10:09.184Z
Reserved: 2025-07-24T07:08:14.587Z
Link: CVE-2025-8107
Updated: 2025-07-24T13:17:15.353Z
Status : Awaiting Analysis
Published: 2025-07-24T08:15:31.037
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-8107
No data.
OpenCVE Enrichment
No data.
EUVD