An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected. | |
Title | Commvault CommServe Web Server Unauthenticated SQL Injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-25T15:49:23.837Z
Updated: 2025-07-25T18:31:26.584Z
Reserved: 2025-04-15T19:15:22.562Z
Link: CVE-2025-34136

Updated: 2025-07-25T18:30:54.527Z

Status : Awaiting Analysis
Published: 2025-07-25T16:15:28.650
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-34136

No data.