CVE-2025-33108: IBM I

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to a library unqualified call made by a BRMS program. A malicious actor could cause user-controlled code to run with component access to the host operating system.

Affected products

  • IBM I: version 7.4 only; version 7.5 only

Published 2025-06-14. Last modified 2026-06-17.