SQL Injection Vulnerability in Commvault Web Server by Commvault Systems
CVE-2025-34136
6.9MEDIUM
What is CVE-2025-34136?
A critical SQL injection vulnerability has been identified in the Web Server component of Commvault, affecting specific versions. This vulnerability enables a remote, unauthenticated attacker to execute malicious SQL commands, potentially compromising the integrity of the database and allowing unauthorized access to sensitive information. It is essential to patch the affected versions to mitigate the risk. Systems with the CommServe and Web Server roles installed are particularly at risk, while other components within the environment remain unaffected.
Affected Version(s)
Commvault Linux 11.32.0 <= 11.32.93
Commvault Linux 11.36.0 <= 11.36.51
Commvault Linux 11.38.0 <= 11.38.19