25 February 2025 IBM i Security Alert: Privilege elevation (02/25/2025)

🚨 Critical Security Alert: IBM i Vulnerability (CVE-2024-55898) – High Risk of Privilege Elevation 🚨

A major vulnerability has been identified in IBM i, exposing systems to a critical risk of elevation of privileges. This vulnerability, referenced as CVE-2024-55898, is due to an uncontrolled search path element, enabling a malicious user to take full control of the system.

🔴 Threat details:
A user with the necessary rights to compile or restore a program can exploit an unqualified library call to execute code with administrator privileges. An attacker could thus compromise the entire IBM i environment by diverting code execution.

📊 Severity index: CVSS 8.5 / 10(Critical)

⚠️ Immediate action to be taken:
It is imperative to apply the patches corresponding to your IBM i version in order to secure your systems. The names of the patches are available in the attachment and must be deployed without delay.

📌 For more information:
See the official IBM online support publication:
🔗 IBM Security Bulletin – CVE-2024-55898

Don’t wait! The longer this vulnerability remains active, the greater the risk of exploitation. Act now to protect your IBM i environments.

Posted in