Attackers can embed a backdoor in the Commvault backup solution
A critical vulnerability jeopardizes Commvault web servers. Admins should secure their systems promptly.
(Image: VideoFlow/Shutterstock.com)
The Commvault backup solution is vulnerable and attackers can compromise computers. Versions equipped against this are available.
Unauthorized access possible
Videos by heise
In a warning message, the developers classify the vulnerability as “critical”. However, they do not list a CVE number. Various Linux and Windows versions are at risk. The developers assure that they have closed the vulnerability in Commvault versions 11.20.216, 11.28.140, 11.32.87 and 11.36.45.
In an unspecified attack scenario, attackers can set up a backdoor on web servers to gain access. So far, there have been no reports of attacks. The developers are not currently explaining how admins can detect such a backdoor.
(des)