CVE-2025-33109: IBM i privilege escalation
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.
Other sources
IBM i is vulnerable to a privilege escalation caused by an invalid database authority check. A bad actor could execute a database procedure or function without having all required permissions, in addition to causing denial of service for some database actions.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-33109?
CVE-2025-33109 has been rated as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-33109?
To mitigate CVE-2025-33109, it is recommended to apply the latest security patches released by IBM for affected versions of the IBM i operating system.
What versions of IBM i are affected by CVE-2025-33109?
CVE-2025-33109 affects IBM i versions 7.2 through 7.6.
What type of attack does CVE-2025-33109 enable?
CVE-2025-33109 enables privilege escalation attacks, allowing unauthorized users to execute database procedures without required permissions.
Can CVE-2025-33109 lead to a denial of service?
Yes, CVE-2025-33109 can cause denial of service for certain database actions as a result of privilege escalation.