Impact
A path traversal flaw in the DataCube component allows an attacker to subvert the security feature that governs data access. This weakness permits manipulation of file paths used by the system, enabling the attacker to read or modify files outside the intended working directory and circumvent built‑in safeguards. The vulnerability could lead to unauthorized disclosure or alteration of sensitive data, thereby compromising confidentiality and integrity of the environment.
Affected Systems
Affected devices run the Commvault Cloud system, specifically the DataCube component. The component is impacted by the path traversal issue and requires an update to the latest maintenance release.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, probably via a payload that crafts an out‑of‑bounds path in a request to the DataCube service.
OpenCVE Enrichment