CVE-2025-2947CWE-278

IBM i privilege escalation

High · published April 17, 2025

CVSS v3.1
7.2
EPSS
0%
Percentile
34.8
In the wild
Unconfirmed
What it is

IBM i 7.6

contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain root access to the host operating system.

The record
Technical detail
CVSS v3.1
7.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00416 · 34.8th percentile
Weakness
CWE-278 · Insecure Preserved Inherited Permissions
Published
2025-04-17T17:10Z
EPSS history
Timeline
  • 17 APR 17:10Z
    IBM i privilege escalation
    cvelistv5