CVE-2025-33109
7.5IBM · i
IBM i is susceptible to a privilege escalation vulnerability due to an improper database authority check, allowing authenticated attackers to execute unauthorized functions or trigger a denial of service.
Executive summary
IBM i operating system releases 7.2 through 7.6 contain a privilege escalation flaw that allows authenticated users to bypass authority checks and impact system availability.
Vulnerability
The vulnerability stems from an invalid database authority check (CWE-250), which permits an authenticated user with low-level access to execute database procedures or functions without the required administrative permissions.
Business impact
Successful exploitation allows an authenticated attacker to perform unauthorized database operations, potentially resulting in data manipulation or severe service disruption. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to the integrity and availability of business-critical database environments.
Remediation
Immediate Action: Apply the specific IBM i 5770-SS1 Program Temporary Fixes (PTFs) listed in the IBM support documentation to resolve this authority check flaw.
Proactive Monitoring: Monitor database audit logs for unusual procedure execution patterns or unauthorized attempts to access restricted database functions.
Compensating Controls: Restrict database access permissions to the absolute minimum required for user roles and utilize database activity monitoring tools to detect anomalous query behavior.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk of privilege escalation within a database environment necessitates prompt remediation to prevent unauthorized administrative actions. Organizations running IBM i versions 7.2 through 7.6 should prioritize the installation of the referenced PTFs during the next scheduled maintenance window to effectively mitigate this security risk.