Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Commvault

Commvault

enriched
Backup as a ServiceData Security Posture Management (DSPM)

Represented by Carahsoft ↗

commvault.com ↗ · required email domain for this vendor's users

Do you work at Commvault?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on Commvault's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of Commvault we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 8 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 2 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 16 published CVE(s) — a public disclosure record exists
    • 4 rated critical
    • No public status page found
  • Limited

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 1 of 3

    How much this vendor volunteers before you have to ask.

    • No bug bounty or vulnerability disclosure policy found
  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against Commvault.

Data coverage: 15/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness25/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 25

IntegrationsUI-12 — integration graphDetected from this vendor's own published integration/partner pages by the enrichment loop — each entry links the exact page it was found on. Directional: "integrates with" is claimed by this vendor; "integrated by" is claimed by the other vendor's site. Coverage grows as the scan progresses.

7 detected

Integrated by: CrowdStrike, Darktrace, Elastio, OctoXLabs, Seceon Inc, UncommonX, Wiz

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

Air-gapped, immutable cloud backup storage for ransomware protection AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

Security & trust signalsAbout these signalsCertifications are keyword-matched from the vendor's own public pages (each claim links to its source — verify directly before relying on it). Security headers are checked live against the vendor's homepage, re-checked every 90 days. Both are independent, automated signals, not a vendor-submitted or audited claim, and are not blended into a single score.

6 of 9 technical checks completed — not a score, just coverage

Security headers (1/5) — checked 8/14/2026

  • ✓ Strict-Transport-Security
  • ✕ Content-Security-Policy
  • ✕ X-Frame-Options
  • ✕ X-Content-Type-Options
  • ✕ Referrer-Policy
  • ✕ security.txt

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL2016201720182019202020212022202320242025CVE-2025-3928 · HIGH 8.8 · 2025-04-25CVE-2025-34028 · CRITICAL 10.0 · 2025-04-22CVE-2021-34997 · HIGH 8.8 · 2022-01-14CVE-2021-34996 · HIGH 8.8 · 2022-01-14CVE-2021-34995 · HIGH 8.8 · 2022-01-14CVE-2021-34994 · HIGH 8.8 · 2022-01-14CVE-2021-34993 · CRITICAL 9.8 · 2022-01-14CVE-2020-25780 · HIGH 7.5 · 2020-10-29CVE-2017-18044 · CRITICAL 9.8 · 2018-01-19CVE-2017-3195 · CRITICAL 9.8 · 2017-12-16CVE-2015-7253 · HIGH 10.0 · 2015-11-04

Known CVEs (16)2 newAbout this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-13738 ↗new2026

    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault in…

  • CVE-2026-13737 ↗new2026

    CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, includ…

  • CVE-2025-34136 ↗2025

    An SQL injection vulnerability exists in Commvault 11.32.0 - 11.32.93, 11.36.0 - 11.36.51, and 11.38.0 - 11.38.19 Web Server component that allows a remote, unauthenticated attacker to perform SQL Inj…

  • CVE-2024-13976 ↗2025

    A DLL injection vulnerability exists in Commvault for Windows 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. During the installation of maintenance updates, an attacker with local access may exploit…

  • CVE-2024-13975 ↗2025

    A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected configurations, a local attacker who owns a client syst…

  • CVE-2025-3928 ↗⚠ actively exploitedHIGH 8.82025

    Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors …

  • CVE-2025-34028 ↗⚠ actively exploitedCRITICAL 10.02025

    The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path tra…

  • CVE-2021-34997 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34996 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34995 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34994 ↗HIGH 8.82022

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the ex…

  • CVE-2021-34993 ↗CRITICAL 9.82022

    This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2020-25780 ↗HIGH 7.52020

    In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead…

  • CVE-2017-18044 ↗CRITICAL 9.82018

    A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the…

  • CVE-2017-3195 ↗CRITICAL 9.82017

    Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution…

  • CVE-2015-7253 ↗HIGH 10.02015

    The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.

Competitors (12)

full alternatives comparison →
1touch.ioAcanteAcsenseActifileAhsay Systems CorporationAlibaba CloudArcserveArexdataAvePointCohesityOdasevaStash Global

Products (15)

Data Security Posture Management (DSPM)

1
  • Commvault Security IQAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Data protection platform with security posture scoring and threat detection

Backup as a Service

14
  • Commvault Air Gap ProtectAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Air-gapped, immutable cloud backup storage for ransomware protection
  • Commvault Cloud Cyber RecoveryAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-based backup, recovery, and cyber resilience platform for hybrid envs
  • Commvault Cloud UnityAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-native platform for data security, identity resilience, and cyber recovery
  • Commvault Cloud for GovernmentAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    FedRAMP High authorized backup, recovery & DR solution for government entities
  • Commvault Complete Data ProtectionAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Database backup and recovery platform for AI, cloud, and on-premises databases
  • Commvault Distributed StorageAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Distributed storage solution for data backup (EOA announced, EOL 2026)
  • Commvault Endpoint Backup and RecoveryAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Endpoint backup and recovery solution for laptops and desktops
  • Commvault File Object and ArchiveAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-based file, object, and archive management with compliance capabilities
  • Commvault HyperScale FlexAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Scalable backup & recovery solution for multi-petabyte workloads & datasets
  • Commvault HyperScale XAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Integrated backup & recovery platform with scale-out storage for hybrid cloud
  • Commvault Kubernetes BackupAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Enterprise backup and recovery solution for Kubernetes workloads and data
  • Commvault Microsoft 365 BackupAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-based backup and recovery solution for Microsoft 365 workloads
  • Commvault Salesforce BackupAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-based backup and recovery solution for Salesforce environments
  • Commvault VM BackupAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-native VM backup and recovery platform for hybrid cloud environments