IBM i privilege escalation
Published May 17, 2025
8.8
HIGHCVSS 3.1
EPSS 0.43%
Description
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.
Affected products
-
- Version 7.2StatusaffectedConstraints-
- Version 7.3StatusaffectedConstraints-
- Version 7.4StatusaffectedConstraints-
- Version 7.5StatusaffectedConstraints-
- Version 7.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| IBM | n/a | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The issue can be addressed by applying a PTF to IBM i. IBM i release 7.6, 7.5, 7.4, 7.3, 7.2 will be fixed. The IBM i 5770-TC1 PTF numbers listed below resolve the vulnerability.
IBM i Release 5770-TC1 PTF Number PTF Download Link 7.6 SJ05513 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05513 7.5 SJ05494 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05494 7.4 SJ05505 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05505 7.3 SJ05514 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05514 7.2 SJ05525 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ05525
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15589 Advisory
- https://www.ibm.com/support/pages/node/7233799 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15589 | Advisory | |
| https://www.ibm.com/support/pages/node/7233799 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.