Commvault is a widely adopted enterprise-grade backup and data protection platform, available as both a SaaS and on-premises solution. Large organizations and managed service providers commonly deploy the Windows on-premises appliance (Innovation Release 11.38.x) in environments requiring high security standards and zero-trust controls.
| Date | 2025-05-05 09:50:14 |
| Information |
|
Technical Summary
An attacker can exploit two unauthenticated endpoints — deployWebpackage.do and deployServiceCommcell.do — to achieve remote code execution by combining:
SSRF Injection
- The
commcellNameparameter is interpolated directly into an HTTPS GET request (https://<commcellName>/commandcenter/webpackage.do) without hostname validation. - This allows the server to retrieve attacker-controlled content from arbitrary hosts.
- The
Arbitrary File Write and Directory Traversal
- The retrieved response (usually a ZIP archive) is written to disk in a path derived from the
servicePackparameter. - By inserting path traversal sequences (e.g.,
../../Reports/MetricsUpload/shell/), an attacker can write files to web-accessible directories such as/Reports/MetricsUpload/….
- The retrieved response (usually a ZIP archive) is written to disk in a path derived from the
JSP Upload and Execution
- A malicious ZIP archive containing
.jsppayloads is extracted into the target directory (e.g.,…/shell/.tmp/dist-cc/dist-cc/). - The attacker then sends an HTTP GET request to the deployed JSP file, achieving arbitrary code execution under the Tomcat process.
- A malicious ZIP archive containing
Alternative Upload via Multipart
- The
deployServiceCommcell.doendpoint accepts a multipart file upload, bypassing external HTTP retrieval entirely and providing untrusted ZIP content directly to the same vulnerable deployment routine.
- The
Recommendations
Immediate Patching: Update all on-premises appliances to Innovation Release 11.38.20 or higher, in accordance with Commvault Security Advisory CV202504_1.
Network Controls: Implement egress filtering or host allow-listing to prevent SSRF attacks — block untrusted hostnames/IPs that the backup server can reach.
Input Validation: Ensure server-side sanitization of all user-supplied parameters used in file system contexts or HTTP requests.
Principle of Least Privilege: Run Commvault services with a dedicated account with minimal write access — prevent writes to the webroot and configuration directories.
Monitoring and Detection:
- Check logs for unexpected calls to
deployWebpackage.doanddeployServiceCommcell.do. - Perform scans to identify the creation of suspicious ZIP files or new JSP files in web-accessible paths.
- Check logs for unexpected calls to
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
