CVE Explorer
CVE-2025-8107
In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.
This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-668","description":"CWE-668 Exposure of Resource to Wrong Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-269","description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","platforms":["Oracle Tenant Mode"],"product":"OceanBase Server","vendor":"OB","versions":[{"lessThan":"3.2.4.8","status":"affected","version":"3.2.4.x","versionType":"rpm"},{"lessThan":"4.2.1.10","status":"affected","version":"4.2.1 x","versionType":"rpm"},{"lessThan":"4.2.5","status":"affected","version":"4.2.x","versionType":"rpm"},{"lessThan":"4.3.3.2","status":"affected","version":"4.3.3.x","versionType":"rpm"},{"status":"unaffected","version":"4.3.4","versionType":"rpm"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-668","description":"CWE-668 Exposure of Resource to Wrong Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-269","description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"url":"https://github.com/oceanbase/oceanbase/security"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:dd8218252155b80dc7c920e7c85c331290d5b873d5eabfa55926ce5421fc72c5 · sha256:a909d26a233aaad4… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.