Medium SQL Injection Vulnerability
This medium-severity Commvault advisory covers CV_2025_04_2.
Android app · Google Play
Monitor Commvault CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Save as PDF A security vulnerability has been identified in the CommServe and Web Server installation that allows a remote SQL Injection attack without authentication. Other installations in the same system are not compromised by this vulnerability.CVSS Score: 5.5
- Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.32.0 - 11.32.93 11.32.94 Resolved Commvault Linux, Windows 11.36.0 - 11.36.51 11.36.52 Resolved Commvault Linux, Windows 11.38.0 - 11.38.19 11.38.20 Resolved
- 11.32.0
- 11.32.93
- 11.32.94
- 11.36.0
- 11.36.51
- 11.36.52
- 11.38.0
- 11.38.19
- 11.38.20
- Affected Versions
- 11.32.0 - 11.32.93
- 11.36.0 - 11.36.51
- 11.38.0 - 11.38.19
Official advisory · medium-confidence parse· fetched 2 months ago·verify at source
- 11.32.94
- 11.36.52
- 11.38.20
Official advisory · medium-confidence parse· fetched 2 months ago·verify at source
Mitigation checklist
- Install the listed maintenance release (or a more recent one) for your feature release: 11.32.94, 11.36.52, 11.38.20.
Official advisory · medium-confidence parse· fetched 2 months ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.