CVE-2025-36367: IBM i is affected by a privilege escalation in IBM i SQL services

Published Oct 31, 2025
·
Updated

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.

Other sources

IBM i is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check.  A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.

IBM

Affected Software

11 affected components
IBM IBM i>=7.2<=7.6
IBM i<=7.6
IBM i<=7.5
IBM i<=7.4
IBM i<=7.3
IBM i<=7.2
IBM i=7.2
IBM i=7.3
IBM i=7.4
IBM i=7.5
IBM i=7.6

Remediation

Information

Remediation/Fixes IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-SS1 PTF Number(s) PTF Download Link(s) 7.6 SJ07552 SJ07650 SJ07651 SJ07652 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07552 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07650 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07651 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07652 7.5 SJ07553 SJ07653 SJ07654 SJ07655 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07553 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07653 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07654 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07655 7.4 SJ07554 SJ07656 SJ07657 SJ07658 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07554 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07656 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07657 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07658 7.3 SJ07555 SJ07659 SJ07660 SJ07661 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07555 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07659 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07660 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07661 7.2 SJ07556 SJ07662 SJ07663 SJ07664 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07556 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07662 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07663 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ07664 IBM recommends that all users running unsupported versions of affected products upgrade to a supported version of the affected product.

Event History

Oct 31, 2025
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Nov 1, 2025
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-36367?

CVE-2025-36367 is rated as a critical vulnerability due to its potential for privilege escalation.

2

How do I fix CVE-2025-36367?

To fix CVE-2025-36367, apply the latest security patches provided by IBM for your version of IBM i.

3

What versions of IBM i are affected by CVE-2025-36367?

CVE-2025-36367 affects IBM i versions 7.2 through 7.6.

4

What types of attacks can be executed using CVE-2025-36367?

CVE-2025-36367 can be exploited to execute privilege escalation attacks, allowing unauthorized users to gain root access.

5

Is there a workaround for CVE-2025-36367 before applying the patch?

Currently, there are no recommended workarounds for CVE-2025-36367, so it is essential to apply the patch as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203