MEDIUM
Commvault CommServe Web Server Unauthenticated SQL Injection
Published Jul 25, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.46%
Description
An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.
Affected products
-
Affected
- ≥ 11.32.0, ≤ 11.32.93
- ≥ 11.36.0, ≤ 11.36.51
- ≥ 11.38.0, ≤ 11.38.19
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://documentation.commvault.com/securityadvisories/CV_2025_04_2.html vendor-advisorypatch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22723 Advisory
- https://www.vulncheck.com/advisories/commvault-commserve-web-server-unauth-sqli third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://documentation.commvault.com/securityadvisories/CV_2025_04_2.html | vendor-advisorypatch | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22723 | Advisory | |
| https://www.vulncheck.com/advisories/commvault-commserve-web-server-unauth-sqli | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 25, 2025
Updated Nov 19, 2025
Reserved Apr 15, 2025
Link CVE-2025-34136
CISA Vulnrichment
Updated Jul 25, 2025
Red Hat
No data
GitHub
No data