CVE-2025-36367: IBM i is affected by a privilege escalation in IBM i SQL services
IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.
Other sources
IBM i is vulnerable to privilege escalation caused by an invalid IBM i SQL services authorization check. A malicious actor can use the elevated privileges of another user profile to gain root access to the host operating system.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36367?
CVE-2025-36367 is rated as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-36367?
To fix CVE-2025-36367, apply the latest security patches provided by IBM for your version of IBM i.
What versions of IBM i are affected by CVE-2025-36367?
CVE-2025-36367 affects IBM i versions 7.2 through 7.6.
What types of attacks can be executed using CVE-2025-36367?
CVE-2025-36367 can be exploited to execute privilege escalation attacks, allowing unauthorized users to gain root access.
Is there a workaround for CVE-2025-36367 before applying the patch?
Currently, there are no recommended workarounds for CVE-2025-36367, so it is essential to apply the patch as soon as possible.