Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22723 | An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected. |
Wed, 19 Nov 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commvault
Commvault commvault |
|
| CPEs | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Commvault
Commvault commvault |
Fri, 25 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected. | |
| Title | Commvault CommServe Web Server Unauthenticated SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-19T01:28:56.047Z
Reserved: 2025-04-15T19:15:22.562Z
Link: CVE-2025-34136
Updated: 2025-07-25T18:30:54.527Z
Status : Deferred
Published: 2025-07-25T16:15:28.650
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-34136
No data.
OpenCVE Enrichment
No data.
EUVD