An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.
Metrics
Affected Vendors & Products
References
History
Fri, 25 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected. | |
| Title | Commvault CommServe Web Server Unauthenticated SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-25T15:49:23.837Z
Updated: 2025-07-25T18:31:26.584Z
Reserved: 2025-04-15T19:15:22.562Z
Link: CVE-2025-34136
Updated: 2025-07-25T18:30:54.527Z
Status : Awaiting Analysis
Published: 2025-07-25T16:15:28.650
Modified: 2025-07-29T14:14:55.157
Link: CVE-2025-34136
No data.
ReportizFlow