« Volver al listado

CVE-2025-8107

Estado: AplazadaMedia (6.3)—

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.

This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-8107",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-8107",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-24T13:17:13.783053Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "7f247420-63a8-4d59-ac93-d85dd04cd014",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "7f247420-63a8-4d59-ac93-d85dd04cd014",
      "affectedData": [
        {
          "vendor": "OB",
          "product": "OceanBase Server",
          "versions": [
            {
              "status": "affected",
              "version": "3.2.4.x",
              "lessThan": "3.2.4.8",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "4.2.1 x",
              "lessThan": "4.2.1.10",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "4.2.x",
              "lessThan": "4.2.5",
              "versionType": "rpm"
            },
            {
              "status": "affected",
              "version": "4.3.3.x",
              "lessThan": "4.3.3.2",
              "versionType": "rpm"
            },
            {
              "status": "unaffected",
              "version": "4.3.4",
              "versionType": "rpm"
            }
          ],
          "platforms": [
            "Oracle Tenant Mode"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-07-24T08:15:31.037",
  "references": [
    {
      "url": "https://github.com/oceanbase/oceanbase/security",
      "source": "7f247420-63a8-4d59-ac93-d85dd04cd014"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "7f247420-63a8-4d59-ac93-d85dd04cd014",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        },
        {
          "lang": "en",
          "value": "CWE-668"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands.\n\n\n\n\nThis vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected."
    },
    {
      "lang": "es",
      "value": "En el modo de inquilino Oracle de OceanBase, un usuario malintencionado con privilegios específicos puede escalar privilegios a nivel de sistema mediante la ejecución de comandos cuidadosamente manipulados. Esta vulnerabilidad solo afecta a los inquilinos de OceanBase en modo Oracle. Los inquilinos en modo MySQL no se ven afectados."
    }
  ],
  "lastModified": "2026-06-17T10:06:19.030",
  "sourceIdentifier": "7f247420-63a8-4d59-ac93-d85dd04cd014"
}