Impact
A condition in the Private Metrics Server allows an attacker to inject arbitrary SQL commands into database operations, potentially enabling unauthorized read, modification, or deletion of metric data. This flaw exposes sensitive configuration and usage information that could be leveraged to compromise overall system integrity and confidentiality. The vulnerability manifests as an injection flaw that could allow remote exploitation if the metrics interface is reachable from untrusted sources.
Affected Systems
The affected product is Commvault Cloud Private Metrics Server. Specific version information is not provided in the CVE data, so users should confirm whether their installation is affected by consulting release notes or the vendor’s advisories.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity, indicating significant potential impact if exploited. The EPSS score is unavailable, so the likelihood of exploitation is unknown, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a network-based attack via the metrics interface, but the exact method is not detailed in the CVE. The vulnerability hinges on unauthenticated or weakly authenticated input reaching the database layer, underscoring the need for patching and input validation.
OpenCVE Enrichment