CVE-2025-2947CWE-278
IBM i privilege escalation
High · published April 17, 2025
What it is
IBM i 7.6
contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.
The record
Technical detail
- CVSS v3.1
- 7.2 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00416 · 34.8th percentile
- Weakness
- CWE-278 · Insecure Preserved Inherited Permissions
- Published
- 2025-04-17T17:10Z
EPSS history
Timeline