CVE-2025-34136: Commvault CommServe Web Server Unauthenticated SQL Injection
An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34136?
CVE-2025-34136 is considered a high severity vulnerability due to its potential to allow remote, unauthenticated SQL injection attacks.
How do I fix CVE-2025-34136?
To fix CVE-2025-34136, upgrade to versions of Commvault CommServe Web Server that are beyond the vulnerable versions specified in the advisory.
What versions of Commvault are affected by CVE-2025-34136?
CVE-2025-34136 affects Commvault versions 11.32.0 to 11.32.93, 11.36.0 to 11.36.51, and 11.38.0 to 11.38.19.
Can CVE-2025-34136 be exploited remotely?
Yes, CVE-2025-34136 can be exploited remotely by unauthenticated attackers, making it particularly dangerous.
What type of vulnerability is CVE-2025-34136?
CVE-2025-34136 is an SQL injection vulnerability that allows attackers to manipulate SQL queries executed by the application.