CVE-2025-8107

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) En el modo de inquilino Oracle de OceanBase, un usuario malintencionado con privilegios específicos puede escalar privilegios a nivel de sistema mediante la ejecución de comandos cuidadosamente manipulados. Esta vulnerabilidad solo afecta a los inquilinos de OceanBase en modo Oracle. Los inquilinos en modo MySQL no se ven afectados.

24 Jul 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 08:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-8107

Mitre link : CVE-2025-8107

CVE.ORG link : CVE-2025-8107


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management

CWE-668

Exposure of Resource to Wrong Sphere