Impact
CommServe contains a path traversal flaw that permits an attacker to construct file paths that escape the intended directory boundaries and retrieve arbitrary files from the underlying operating system. The flaw is triggered when malicious path components are included in requests handled by the CommServe web interface or API. This enables the disclosure of sensitive system files, configuration data, or deployment artifacts, compromising the confidentiality of the infrastructure. The weakness is aligned with CWE-22 Path Traversal. Based on the description, the likely attack vector is through the CommServe web interface or API that accepts file path parameters.
Affected Systems
Customers who run the Commvault Cloud CommServe component are impacted. The advisory does not specify a version range; it simply recommends upgrading to the latest maintenance release that incorporates the fix. No other product or firmware versions are explicitly mentioned.
Risk and Exploitability
The vulnerability scores a CVSS of 8.3, reflecting high potential for information disclosure. EPSS data is not available, and the flaw is not listed in the CISA known exploited vulnerabilities catalog, indicating no confirmed exploitation to date. Assuming an attacker can reach the CommServe instance over the network, the path traversal can be triggered without special privileges and may allow the reading of arbitrary files, providing a covert channel for stealing sensitive data. Based on the description, the likely attack vector is remote access to CommServe over the network. The remediation urgency is therefore high, especially for services exposed to untrusted networks.
OpenCVE Enrichment