Skip to main content
Answer

Apache Vulnerability CVE-2022-24112 - Is this affecting Commvault ?

  • March 29, 2022
  • 6 replies
  • 298 views

Forum|alt.badge.img

May I know if Apache Vulnerability CVE-2022-24112 is affecting Commvault

CVE-2022-24112/CVE-2022-24112.yaml at main · Mr-xn/CVE-2022-24112 · GitHub

Best answer by Sean Crifasi

We use Apache Tomcat to provide Web Console functionality. 

Reviewing the CVE posted this is explicitly related to a separate product “Apache APISIX” I have not found any indication, documentation, or prior case with apisix deployed with Commvault. If you do have this present on your server, kindly confirm the path in which this is found.

If you have a question or comment, please create a topic

6 replies

Mike Struening
Vaulter
Forum|alt.badge.img+22

@Harwie , let me look into this for you.


Forum|alt.badge.img
  • Author
  • Vaulter
  • April 7, 2022

@Mike Struening , May I have an update on this?

 

Thanks

 

Harwie


Mike Struening
Vaulter
Forum|alt.badge.img+22

Still digging, though I see you have a case for this.  Keep me posted and I’ll do the same.


Forum|alt.badge.img
  • Author
  • Vaulter
  • April 13, 2022

Hi Mike,

 

Any update on this Apache vulnerability?

 

 


Sean Crifasi
Vaulter
Forum|alt.badge.img+9
  • Vaulter
  • Answer
  • April 13, 2022

We use Apache Tomcat to provide Web Console functionality. 

Reviewing the CVE posted this is explicitly related to a separate product “Apache APISIX” I have not found any indication, documentation, or prior case with apisix deployed with Commvault. If you do have this present on your server, kindly confirm the path in which this is found.


Forum|alt.badge.img
  • Author
  • Vaulter
  • April 13, 2022

Hi Sean,

Thanks for your reply, I will update this to the customer.