Arbitrary Code Execution in Commvault CommCell by Commvault
CVE-2021-34994
What is CVE-2021-34994?
This vulnerability enables remote attackers to execute arbitrary code on vulnerable instances of Commvault CommCell 11.22.22. Although the exploitation requires authentication, the existing authentication mechanism can be bypassed. The root cause of this vulnerability lies within the DataProvider class, where there is inadequate validation of user-supplied input before it is executed as JavaScript code. This allows an attacker to escape the JavaScript sandbox, leading to the potential execution of Java code with elevated privileges in the context of NETWORK SERVICE.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CommCell 11.22.22
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
