Commvault Web Server Unauthenticated SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the Commvault Web Server component, affecting versions 11.32.0 prior to 11.32.93, 11.36.0 prior to 11.36.51, and 11.38.0 prior to 11.38.19. This vulnerability allows remote, unauthenticated attackers to perform SQL injection attacks on systems where the CommServe and Web Server roles are installed. Other Commvault components in the same environment are not affected.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries and potentially access or modify database information.

Remediation

Users are advised to update to Commvault versions 11.32.94, 11.36.52, or 11.38.20. For more information on installing Commvault software updates, refer to the Commvault documentation on 'Installing Commvault Software Updates on Demand'. If the update cannot be applied, isolate the Command Center and Web Server installation from external network access.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
3.1
exploitability
7.0
remediation
7.9
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.