NONE · 0

CVE-2025-34136

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Inj...

Vulnerability Description

An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Injection. The vulnerability impacts systems where the CommServe and Web Server roles are installed. Other Commvault components deployed in the same environment are not affected.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-34136?

CVE-2025-34136 is a documented vulnerability. An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Inj...

How severe is CVE-2025-34136?

CVSS scoring is not yet available for CVE-2025-34136. Check NVD for updates.

Is there a patch for CVE-2025-34136?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.