CRITICAL

CVE-2025-34028

Commvault Commvault 2025-04-22 CVSS v3.1
CVSS
10
KEV

Description

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP.





This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

Summary dbcve.org

A path traversal vulnerability in Commvault Command Center Innovation Release versions 11.38.0-11.38.20 allows unauthenticated attackers to upload malicious ZIP install packages that, when extracted by the server, can write files to arbitrary filesystem locations, leading to remote code execution via malicious JSP files.

Mitigation

Upgrade to version 11.38.20 with SP38-CU20-433 or SP38-CU20-436, or upgrade to version 11.38.25 with SP38-CU25-434 or SP38-CU25-438; until patched, disable unauthenticated access to Command Center or place it behind a firewall.

Proof of Concept

Weakness (CWE)

CWE-22 Path Traversal
CWE-306 Missing Authentication

EPSS Score

97.55%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE