vulnerability
Commvault Web Server: CVE-2025-57789: Storing Passwords in a Recoverable Format
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:S/C:P/I:P/A:N) | Aug 20, 2025 | Aug 20, 2025 | Aug 20, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
Aug 20, 2025
Added
Aug 20, 2025
Modified
Aug 20, 2025
Description
An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
Solution
commvault-web-server-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.