Back

MEDIUM

Commvault CommServe Web Server Unauthenticated SQL Injection

Published Jul 25, 2025

Description

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Jul 25, 2025
Updated Nov 19, 2025
Reserved Apr 15, 2025

CISA Vulnrichment

Updated Jul 25, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Jul 25, 2025
Updated Nov 19, 2025

GitHub

No data