Skip to main content
Solved

vulnerability/CVE-2025-59250

  • October 20, 2025
  • 4 replies
  • 145 views

Forum|alt.badge.img+16

Hello,

 

I got email about  Vulnerability in the JDBC Driver for SQL Server (Microsoft) does its effect commvault sql agent? 

 

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-59250

 

Best answer by Pradeep

Hi ​@Egor Skepko ,

This requires a detailed review the CVE was released this month and needs further investigation before any conclusions can be drawn.

We recommend logging a support ticket so the issue can be examined thoroughly by the appropriate teams.

4 replies

Forum|alt.badge.img+12
  • Vaulter
  • October 21, 2025

Hi ​@Egor Skepko ,

Thanks for highlighting the latest CVE identified on SQL Server (CVE-2025-59250).
However, the SQL Server on the CommServe is configured using the ODBC driver, not the JDBC driver.

That said, I would still recommend gathering the below details and opening a support case to confirm there are no dependencies or indirect impact related to CVE-2025-59250:

  • Details of the SQL Server and Commvault version and driver configuration in use.

  • Any third-party or integrated components that may utilize JDBC connectivity.

This will help validate that the CommServe environment is not affected by this vulnerability and we can review and confirm.


https://documentation.commvault.com/v11/commcell-console/pre_installing_microsoft_sql_server_software_on_non_cluster_environment.html


Forum|alt.badge.img+16
  • Author
  • Novice
  • October 21, 2025

@Pradeep What about clients where sql agent are installed, its usinng sqljbdc_aut.dll (native token) and version is not up to date 

On the commserver we are using versie 17 of odbc and not jbdc 

 


Forum|alt.badge.img+12
  • Vaulter
  • Answer
  • October 21, 2025

Hi ​@Egor Skepko ,

This requires a detailed review the CVE was released this month and needs further investigation before any conclusions can be drawn.

We recommend logging a support ticket so the issue can be examined thoroughly by the appropriate teams.


Forum|alt.badge.img+16
  • Author
  • Novice
  • October 21, 2025

@Pradeep Ok i wil create case at commvault. Thank you.