CVE-2025-33109
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-24

Last updated on: 2025-08-11

Assigner: IBM Corporation

Description
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-24
Last Modified
2025-08-11
Generated
2026-05-07
AI Q&A
2025-07-24
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
ibm i 7.6
ibm i 7.2
ibm i 7.3
ibm i 7.4
ibm i 7.5
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in IBM i versions 7.2 through 7.6 is a privilege escalation caused by an invalid database authority check. It allows an attacker to execute database procedures or functions without having all the required permissions. Additionally, exploiting this flaw can cause denial of service for some database actions. The vulnerability is classified under CWE-250 (Execution with Unnecessary Privileges) and has a CVSS v3.1 base score of 7.5, indicating a high impact on confidentiality, integrity, and availability. [1]


How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker with low privileges to escalate their privileges by executing database procedures or functions without proper authorization. This can lead to unauthorized access to sensitive data, modification or corruption of data, and disruption of database services through denial of service attacks, impacting confidentiality, integrity, and availability of the system. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should apply the appropriate Program Temporary Fixes (PTFs) released by IBM for your IBM i version under the 5770-SS1 product identifier. The PTF numbers vary by version (e.g., SJ05809, SJ05810, etc. for IBM i 7.6). If you are running unsupported versions, IBM recommends upgrading to supported and patched versions, as no workarounds or mitigations are available. Regularly check IBM’s support website for the latest fixes and updates. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart