PT-2025-30892 · Commvault · Commvault

Published

2025-07-25

·

Updated

2025-07-25

·

CVE-2025-34136

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Commvault versions 11.32.0 through 11.32.93 Commvault versions 11.36.0 through 11.36.51 Commvault versions 11.38.0 through 11.38.19
Description An SQL injection vulnerability exists in the Web Server component that could allow a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.
Recommendations Commvault versions 11.32.0 through 11.32.93: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Commvault versions 11.36.0 through 11.36.51: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Commvault versions 11.38.0 through 11.38.19: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34136

Affected Products

Commvault