CVE-2025-8107

MEDIUM

OceanBase <Oracle Mode - Privilege Escalation

Title source: llm
STIX 2.1

Description

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

Scores

CVSS v3 6.3
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269 CWE-668
Status published
Products (5)
OB/OceanBase Server 3.2.4.x - 3.2.4.8
OB/OceanBase Server 4.2.1 x - 4.2.1.10
OB/OceanBase Server 4.2.x - 4.2.5
OB/OceanBase Server 4.3.3.x - 4.3.3.2
OB/OceanBase Server 4.3.4
Published Jul 24, 2025
Tracked Since Feb 18, 2026