A high-severity vulnerability (CVE-2025-33108) in IBM Backup, Recovery, and Media Services (BRMS) for IBM i versions 7.4 and 7.5 enables privilege escalation through unqualified library calls.
This flaw allows attackers with program compilation or restoration privileges to execute arbitrary code with elevated system access, posing significant risks to enterprise environments.
The vulnerability stems from CWE-250: Execution with Unnecessary Privileges, where BRMS programs make unqualified library calls without specifying secure paths.
This oversight enables malicious actors to hijack library references, redirecting them to attacker-controlled code.
Key technical elements:
BRMS component’s failure to validate library paths during program compilation/restoration.IBM confirmed the flaw could allow “user-controlled code to run with component access to the host operating system,” potentially compromising entire IBM i environments.
The vulnerability exposes organizations to:
| Risk Factor | Details |
|---|---|
| Severity | High (CVSS 8.5) – enables full system control |
| Affected Systems | IBM i 7.4/7.5 with BRMS installed |
| Exploit Complexity | Requires existing user privileges to compile/restore programs |
| Remediation Status | Patches available via PTFs SJ05906 (7.4) and SJ05907 (7.5) |
Successful exploitation could lead to:
IBM released Program Temporary Fixes (PTFs) to address the vulnerability:
BRMS activity logs for unexpected library paths.While no workarounds exist, combining patches with least-privilege access models significantly reduces attack surfaces.
Organizations using legacy IBM i systems should prioritize patching, given BRMS’s central role in enterprise backup infrastructure.
This vulnerability highlights the critical need for rigorous library path validation in privileged services.
With IBM i systems widely used in financial and healthcare sectors, timely remediation is essential to prevent systemic compromises.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
The post IBM Backup Services Vulnerability Allows Attackers to Escalate Privileges appeared first on Cyber Security News.
In January, Qualcomm hinted to The Verge that it might finally bring its powerful Arm-based…
Students are seen on the campus of Columbia University on April 14, 2025, in New…
If you’ve been waiting to grab any video games, today might be the day. On…
I first took notice of Samson: A Tyndalston Story when its team of former Just…
Stardew Valley creator Eric Barone (ConcernedApe) has released a 10th anniversary video revealing, among other…
Highguard studio Wildlight Entertainment reportedly has less than 20 people remaining to work on the…
This website uses cookies.