Back

HIGH

IBM i privilege escalation

Published May 17, 2025

Description

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.

Affected products

Remediation

Vendor solution

The issue can be addressed by applying a PTF to IBM i. IBM i release 7.6, 7.5, 7.4, 7.3, 7.2 will be fixed. The IBM i 5770-TC1 PTF numbers listed below resolve the vulnerability.

IBM i Release 5770-TC1 PTF Number PTF Download Link 7.6 SJ05513 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05513 7.5 SJ05494 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05494 7.4 SJ05505 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05505 7.3 SJ05514 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05514 7.2 SJ05525 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05525

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published May 17, 2025
Updated Feb 26, 2026
Reserved Apr 15, 2025
CISA Vulnrichment
Updated May 20, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ibm
Published May 17, 2025
Updated Feb 26, 2026
Exploited since n/a
EUVD-2025-15589