This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22483 | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. |
| Link | Providers |
|---|---|
| https://github.com/oceanbase/oceanbase/security |
|
Thu, 24 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. | |
| Weaknesses | CWE-269 CWE-668 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: OB
Published:
Updated: 2025-07-31T09:10:09.184Z
Reserved: 2025-07-24T07:08:14.587Z
Link: CVE-2025-8107
Updated: 2025-07-24T13:17:15.353Z
Status : Deferred
Published: 2025-07-24T08:15:31.037
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8107
No data.
OpenCVE Enrichment
No data.
EUVD