Target Industry
Indiscriminate, opportunistic targeting.
Overview
A high-severity vulnerability affecting IBM Backup, Recovery, and Media Services (BRMS), a tool for automating and managing backup, recovery, and media management processes on IBM i systems, has been discovered. The vulnerability, tracked as CVE-2025-33108 (CVSS Score 8.5), arises from an unqualified library call made by a BRMS programme, allowing a user with the capability to compile or restore a programme to gain elevated privileges.
Impact
The impact of CVE-2025-33108 is significant as it allows unauthorised users to execute arbitrary code with elevated system privileges, potentially compromising the integrity of the host operating system. This could lead to unauthorised access to sensitive data, operational disruptions, and significant financial losses due to system downtime or data breaches.
Affected Products
IBM Backup, Recovery, and Media Services for i versions 7.4 and 7.5.
Exploitation
The vulnerability arises from the BRMS software referencing system resources without specifying secure paths, enabling threat actors to redirect those calls to their own code. Consequently, a threat actor with compile or restore capabilities can exploit this vulnerability to run user-controlled code with elevated privileges, potentially gaining full system access and compromising the integrity of the affected IBM i environment.
Containment, Mitigations & Remediations
To mitigate the risks associated with CVE-2025-33108, organisations should immediately apply the Program Temporary Fixes (PTFs) provided by IBM: PTF SJ05907 for IBM i 7.5 and PTF SJ05906 for IBM i 7.4. Additionally, restricting user privileges, implementing strict access controls, and monitoring programme compilation and restoration activities are recommended. Network segmentation can also help limit potential attack surfaces.
Threat Landscape
The threat landscape for CVE-2025-33108 includes a variety of threat actors who may seek to exploit vulnerabilities in enterprise systems for financial gain, data theft, or disruption of services. The potential for exploitation exists in any organisation using the affected versions of IBM software, making it a widespread concern.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information













