Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-101454
HistoryNov 23, 2021 - 12:00 a.m.

Commvault CommCell Arbitrary File Upload Vulnerability

2021-11-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.031 Low

EPSS

Percentile

91.2%

Commvault CommCell enables fast, large-scale backup and recovery of virtual machines, structured and unstructured data.An arbitrary file upload vulnerability exists in the AppStudioUploadHandler class in versions of Commvault CommCell prior to 11.25, which stems from a lack of proper validation of user-supplied data. An attacker could exploit this vulnerability to execute code in the context of NETWORK SERVICE.

CPENameOperatorVersion
commvault commcelllt11.25

0.031 Low

EPSS

Percentile

91.2%

Related for CNVD-2021-101454