The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
An attacker without any authentication (CWE-306) uploads a crafted ZIP archive impersonating an installation package. During extraction, the server does not properly validate the paths contained in the archive (CWE-22 – path traversal), allowing a JSP file to be written to any location accessible to the application server. The malicious JSP file placed this way is then executed by the server, resulting in full Remote Code Execution in the context of the server process.
An attacker gains the ability to execute arbitrary code on the server without any authentication, which in practice means complete takeover of the system, including the ability to compromise the integrity and availability of data managed by Commvault.
Commvault Command Center should be updated to a version containing one of the following patches: SP38-CU20-433 or SP38-CU20-436 (for the 11.38.20 line) or SP38-CU25-434 or SP38-CU25-438 (for the 11.38.25 line). Detailed instructions are available in the vendor's official security bulletin at the address indicated in the references (CV_2025_04_1).
Commvault Command Center Innovation Release in versions from 11.38.0 to 11.38.20 and 11.38.25 (before applying appropriate patches); products running on Microsoft Windows and Linux.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCommvault
APPCommvault11.38.0 – 11.38.20 (excl.)Linux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versions
CISA KEV — detailsi
- Vendori
- Commvault
- Producti
- Command Center
- Added to KEVi
- May 2, 2025
- Remediation deadline (US Federal)i
- May 23, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.
Related vulnerabilities
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
RCE przez YAML deserialization w IBM Aspera Faspex