The following table lists security advisories for the Commvault software. To report a new vulnerability, click here.
Advisory ID |
Impact |
Synopsis |
CVEs |
Updated |
Issued |
|---|---|---|---|---|---|
None |
OpenSSH Security Regression (CVE-2006-5051) Vulnerability |
|
|
||
Yes |
SQL Injection and Command Injection Advisory |
None |
|
|
|
None |
Curl advisory |
|
|
||
Yes |
Security vulnerability in Windows access nodes that are used for file server data protection |
None |
|
|
|
Yes |
DLL Injection Vulnerability in the Software Installation Path |
None |
|
|
|
None |
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability |
|
|
||
Yes |
Critical Webserver Vulnerability |
|
|
||
None |
Apache Tomcat Remote Code Execution (CVE-2025-24813) Vulnerability |
|
|
||
Yes |
Vulnerability in Commvault Command Center Installation |
|
|
||
Yes |
SQL Injection Vulnerability |
None |
|
|
|
None |
Tomcat Denial of Service Vulnerabilities |
None |
|
|
|
None |
Handling Report Export Functionality |
None |
|
|
|
Yes |
Stored Cross-Site Scripting Vulnerability |
None |
|
|
|
None |
Authorization Schema Access Controls |
None |
|
|
|
Yes |
Argument Injection Vulnerability in CommServe |
|
|
||
Yes |
Path Traversal Vulnerability |
|
|
||
Yes |
Unauthorized API Access Risk |
|
|
||
Yes |
Vulnerability in Initial Administrator Login Process |
|
|
||
None |
Red Hat Enterprise Linux (RHEL) Malicious Injection Vulnerability |
|
|
||
None |
Apache Struts 2 Vulnerability |
|
|
||
None |
Heap Based Buffer Overflow Vulnerability in cURL |
|
|
||
Yes |
Remote Code Execution Vulnerability in Apache ActiveMQ |
|
|
||
Yes |
Libwebp Vulnerability |
|
|
||
Yes |
Volt Typhoon Advisory |
None |
|
|
|
None |
Remote Memory Corruption Vulnerability in OpenSSL |
|
|
||
None |
Remote Code Execution Vulnerability in Apache Common Text |
|
|
||
None |
Remote Code Execution Vulnerability in the Spring Framework |
|
|
||
Yes |
Local Privilege Escalation Vulnerability in Polkit's pkexec Utility |
|
|
||
Yes |
Vulnerability in Apache Log4j Logging Libraries Impacting Commvault Products |
CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-4104, CVE-2021-44832 |
|
|
|
Yes |
Authentication Bypass Vulnerabilities on CVWebService Endpoint |
None |
|
|
|
None |
Apache Shiro Spring Boot Improper Authentication |
None |
|
|
|
None |
Spring Expression DoS Vulnerability |
None |
|
|
|
None |
Vulnerability with Carbon Black Software |
None |
|
|
|
None |
Commvault Ransomware Protection Is Safe from RIPlace |
None |
|
|
|
None |
Security Vulnerability With MongoDB Versions |
None |
|
|