CVE-2024-13975
- EPSS 0.12%
- Veröffentlicht 25.07.2025 16:15:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client system with the file server agent installed can compro...
CVE-2025-3928
- EPSS 2.09%
- Veröffentlicht 25.04.2025 15:56:28
- Zuletzt bearbeitet 08.10.2026 12:54:32
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in versio...
- EPSS 97.66%
- Veröffentlicht 22.04.2025 16:32:23
- Zuletzt bearbeitet 06.11.2025 13:57:56
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Cod...
- EPSS 69.75%
- Veröffentlicht 19.01.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:14
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to ...