Target Industry

Indiscriminate, opportunistic targeting. 

Overview

A high-severity vulnerability affecting IBM Backup, Recovery, and Media Services (BRMS), a tool for automating and managing backup, recovery, and media management processes on IBM i systems, has been discovered. The vulnerability, tracked as CVE-2025-33108 (CVSS Score 8.5), arises from an unqualified library call made by a BRMS programme, allowing a user with the capability to compile or restore a programme to gain elevated privileges. 

Impact

The impact of CVE-2025-33108 is significant as it allows unauthorised users to execute arbitrary code with elevated system privileges, potentially compromising the integrity of the host operating system. This could lead to unauthorised access to sensitive data, operational disruptions, and significant financial losses due to system downtime or data breaches.

Affected Products

IBM Backup, Recovery, and Media Services for i versions 7.4 and 7.5.

Exploitation

The vulnerability arises from the BRMS software referencing system resources without specifying secure paths, enabling threat actors to redirect those calls to their own code. Consequently, a threat actor with compile or restore capabilities can exploit this vulnerability to run user-controlled code with elevated privileges, potentially gaining full system access and compromising the integrity of the affected IBM i environment.  

Containment, Mitigations & Remediations

To mitigate the risks associated with CVE-2025-33108, organisations should immediately apply the Program Temporary Fixes (PTFs) provided by IBM: PTF SJ05907 for IBM i 7.5 and PTF SJ05906 for IBM i 7.4. Additionally, restricting user privileges, implementing strict access controls, and monitoring programme compilation and restoration activities are recommended. Network segmentation can also help limit potential attack surfaces.

Threat Landscape

The threat landscape for CVE-2025-33108 includes a variety of threat actors who may seek to exploit vulnerabilities in enterprise systems for financial gain, data theft, or disruption of services. The potential for exploitation exists in any organisation using the affected versions of IBM software, making it a widespread concern. 

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing.

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content