Back to Labs
Security Advisory

CVE-2025-34028

About

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP.

This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

Weakness (CWE):CWE-22CWE-306

Rainforest analyst review

Commvault Command Center (Innovation Release 11.38.0 through 11.38.20) lets an unauthenticated actor upload a ZIP file that the server treats as an install package and expands. The extraction routine does not properly constrain the file paths inside the archive, so a crafted ZIP with path-traversal entries writes a malicious JSP into a web-accessible directory. The attacker then requests that JSP, and the server executes it, yielding unauthenticated remote code execution with the scope of the application.

Commvault Command Center manages backup and recovery across the enterprise, which means it is connected to nearly every critical system and holds the credentials and access needed to read and restore that data, an obvious high-value target for both ransomware and espionage. The flaw carries a CVSS 10, proof-of-concept code was published, and it was added to CISA's KEV list amid reporting of nation-state interest in Commvault environments. Upgrade to a fixed build (11.38.20 with the noted service packs or 11.38.25), remove the Command Center from internet exposure, and hunt for unexpected JSP files and web-shell activity given how directly a backup platform's compromise threatens recovery capability.

References

Related CVEs

Frequently asked questions

What is CVE-2025-34028?

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20.

How severe is CVE-2025-34028?

CVE-2025-34028 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2025-34028 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2025-34028?

Public advisories list the following as affected: commvault, linux kernel, windows. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2025-34028?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email