Pre-authenticated Remote Code Execution via SSRF and Arbitrary File Write in Commvault Innovation Release 11.38.x (CVE-2025-34028)

ISGroup Cybersecurity

Commvault is a widely adopted enterprise-grade backup and data protection platform, available as both a SaaS and on-premises solution. Large organizations and managed service providers commonly deploy the Windows on-premises appliance (Innovation Release 11.38.x) in environments requiring high security standards and zero-trust controls.

Date2025-05-05 09:50:14
Information
  • Trending
  • Fix Available

Technical Summary

An attacker can exploit two unauthenticated endpoints — deployWebpackage.do and deployServiceCommcell.do — to achieve remote code execution by combining:

  1. SSRF Injection

    • The commcellName parameter is interpolated directly into an HTTPS GET request (https://<commcellName>/commandcenter/webpackage.do) without hostname validation.
    • This allows the server to retrieve attacker-controlled content from arbitrary hosts.
  2. Arbitrary File Write and Directory Traversal

    • The retrieved response (usually a ZIP archive) is written to disk in a path derived from the servicePack parameter.
    • By inserting path traversal sequences (e.g., ../../Reports/MetricsUpload/shell/), an attacker can write files to web-accessible directories such as /Reports/MetricsUpload/….
  3. JSP Upload and Execution

    • A malicious ZIP archive containing .jsp payloads is extracted into the target directory (e.g., …/shell/.tmp/dist-cc/dist-cc/).
    • The attacker then sends an HTTP GET request to the deployed JSP file, achieving arbitrary code execution under the Tomcat process.
  4. Alternative Upload via Multipart

    • The deployServiceCommcell.do endpoint accepts a multipart file upload, bypassing external HTTP retrieval entirely and providing untrusted ZIP content directly to the same vulnerable deployment routine.

Recommendations

  • Immediate Patching: Update all on-premises appliances to Innovation Release 11.38.20 or higher, in accordance with Commvault Security Advisory CV202504_1.

  • Network Controls: Implement egress filtering or host allow-listing to prevent SSRF attacks — block untrusted hostnames/IPs that the backup server can reach.

  • Input Validation: Ensure server-side sanitization of all user-supplied parameters used in file system contexts or HTTP requests.

  • Principle of Least Privilege: Run Commvault services with a dedicated account with minimal write access — prevent writes to the webroot and configuration directories.

  • Monitoring and Detection:

    • Check logs for unexpected calls to deployWebpackage.do and deployServiceCommcell.do.
    • Perform scans to identify the creation of suspicious ZIP files or new JSP files in web-accessible paths.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert