Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Commvault before 11.36.60. A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role. | A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role. |
Thu, 21 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commvault commvault
|
|
| CPEs | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Commvault commvault
|
|
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Commvault
Commvault commcell |
|
| Vendors & Products |
Commvault
Commvault commcell |
Wed, 20 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Commvault before 11.36.60. A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role. | |
| Title | Argument Injection Vulnerability in CommServe | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-10T15:41:57.068Z
Reserved: 2025-08-19T18:25:57.338Z
Link: CVE-2025-57791
Updated: 2025-08-20T13:12:28.798Z
Status : Modified
Published: 2025-08-20T04:16:04.360
Modified: 2025-09-10T16:15:40.750
Link: CVE-2025-57791
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:31:30Z