Executive brief
Commvault Command Center Innovation Release contains a path traversal vulnerability where unauthenticated actors can upload malicious ZIP files as install packages. When expanded by the server, these files can lead to remote code execution via malicious JSP files.
Affected products
- Commvault Command Center Innovation Release 11.38.0 to 11.38.20
Timeline
- 2025-05-02: disclosed
- 2025-05-02: kev added: Added to CISA KEV catalog
- 2025-05-02: advisory