SQL Injection Vulnerability in Commvault Web Server by Commvault Systems
CVE-2025-34136
What is CVE-2025-34136?
A critical SQL injection vulnerability has been identified in the Web Server component of Commvault, affecting specific versions. This vulnerability enables a remote, unauthenticated attacker to execute malicious SQL commands, potentially compromising the integrity of the database and allowing unauthorized access to sensitive information. It is essential to patch the affected versions to mitigate the risk. Systems with the CommServe and Web Server roles installed are particularly at risk, while other components within the environment remain unaffected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Commvault Linux 11.32.0 <= 11.32.93
Commvault Linux 11.36.0 <= 11.36.51
Commvault Linux 11.38.0 <= 11.38.19
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
