Known Vulnerabilities for products from Commvault
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Commvault".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-34997 json | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22... | 8.8 - HIGH | 2022-01-13 | 2022-01-22 |
| CVE-2021-34996 json | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22... | 8.8 - HIGH | 2022-01-13 | 2022-01-22 |
| CVE-2021-34995 json | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22... | 8.8 - HIGH | 2022-01-13 | 2022-01-22 |
| CVE-2021-34994 json | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22... | 8.8 - HIGH | 2022-01-13 | 2023-06-26 |
| CVE-2021-34993 json | This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22.... | 9.8 - CRITICAL | 2022-01-13 | 2022-01-22 |
| CVE-2020-25780 json | In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Direct... | 7.5 - HIGH | 2020-10-29 | 2020-11-13 |
| CVE-2017-18044 json | A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message p... | 9.8 - CRITICAL | 2018-01-19 | 2019-10-03 |
| CVE-2017-3195 json | Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-base... | Not Provided | 2017-12-16 | 2025-04-20 |
| CVE-2015-7253 json | The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialize... | Not Provided | 2015-11-04 | 2026-05-06 |
Known software with vulnerabilities from Commvault
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Commvault | Active Directory Idataagent | 9.0.0 |
| Application | Commvault | Base Client | 9.0.0 |
| Application | Commvault | Commcell | 14.68 |
| Application | Commvault | Commcell Console | 9.0.0 |
| Application | Commvault | Commnet Browser | 9.0.0 |
| Application | Commvault | Commserve | 9.0.0 |
| Application | Commvault | Commvault | 11.0 |
| Application | Commvault | Continuous Data Replicator | 9.0.0 |
| Application | Commvault | Continuous Data Replicator Vss Provider | 9.0.0 |
| Application | Commvault | Edge | 11.0.0 |
| Application | Commvault | Exchange Database Idataagent | 9.0.0 |
| Application | Commvault | Exchange Mailbox Archiver Agent | 9.0.0 |
| Application | Commvault | Exchange Webproxy Archiver Agent | 9.0.0 |
| Application | Commvault | Exchange Web Proxy Archiver Agent | 9.0.0 |
| Application | Commvault | File System Idataagent | 9.0.0 |
| Application | Commvault | Galaxy | - |
| Application | Commvault | Media Agent | 9.0.0 |
| Application | Commvault | Owa Proxy Enabler | 9.0.0 |
| Application | Commvault | Resource Pack | 9.0.0 |
| Application | Commvault | Sql Server Idataagent | 9.0.0 |