SQL Injection Vulnerability in Commvault Web Server by Commvault Systems
CVE-2025-34136

6.9MEDIUM

Key Information:

Vendor

Commvault

Status
Vendor
CVE Published:
25 July 2025

What is CVE-2025-34136?

A critical SQL injection vulnerability has been identified in the Web Server component of Commvault, affecting specific versions. This vulnerability enables a remote, unauthenticated attacker to execute malicious SQL commands, potentially compromising the integrity of the database and allowing unauthorized access to sensitive information. It is essential to patch the affected versions to mitigate the risk. Systems with the CommServe and Web Server roles installed are particularly at risk, while other components within the environment remain unaffected.

Affected Version(s)

Commvault Linux 11.32.0 <= 11.32.93

Commvault Linux 11.36.0 <= 11.36.51

Commvault Linux 11.38.0 <= 11.38.19

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.