Security Advisory

CVE-2025-34136

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-25 15:49:23
Last updated 2025-11-19 01:28:56
Assigner VulnCheck
State PUBLISHED

Description

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.