GHSA-wqxv-v2vg-q37xHighCVSS 8.8
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote,...
🔗 CVE IDs covered (1)
📋 Description
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2025-3928
- https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928
- https://www.commvault.com/blogs/notice-security-advisory-update
- https://www.commvault.com/blogs/security-advisory-march-7-2025
- https://www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data
- https://www.cisa.gov/news-events/alerts/2025/05/22/advisory-update-cyber-threat-activity-targeting-commvaults-saas-cloud-application-metallic
- https://www.commvault.com/blogs/customer-security-update
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928
- https://github.com/advisories/GHSA-wqxv-v2vg-q37x