CVE-2025-34136

Severity CVSS v4.0:
MEDIUM
Type:
CWE-89 SQL Injection
Publication date:
25/07/2025
Last modified:
29/07/2025

Description

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.