Skip to content

CVE-2025-34028

Path Traversal — is CVE-2025-34028real, exploitable, or a false positive? Here's the community ground truth.

Critical · CVSS 10EPSS 97.1%CISA KEVCWE-22 · Path Traversal

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.

Published

Embed this verdict
TruePositive verdict for CVE-2025-34028
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2025-34028/badge.svg)](https://www.truepositive.app/cve/CVE-2025-34028)
HTML
<a href="https://www.truepositive.app/cve/CVE-2025-34028"><img src="https://www.truepositive.app/cve/CVE-2025-34028/badge.svg" alt="TruePositive verdict for CVE-2025-34028"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

to add your verdict.

Community real-world severity: Critical (Critical 3) — CVSS base score 10

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

No notes yet — be the first to share what you saw or a fix that worked.

    Same weaknessCWE-22 · Path Traversal.