Commvault
Enterprise backup and cyber resilience.
Scorecard from 0 structured reviews
Exposure signal
ElevatedAn objective, third-party reading of this vendor's own credential hygiene. It is not part of the community scorecard and does not affect any rating on DBSE.
Credentials belonging to 16 of this vendor's own staff appear in infostealer logs, and the most recent staff credential appeared 3 months ago. Their staff hold credentials for 46 distinct external services, which is the surface a successful attack on this vendor could reach. At least one of those credentials opens an identity or administrative system rather than an ordinary business one, which is the part that matters most. This says nothing about how well the product works.
Customer-side infections: 762 (not counted in the band)
These are infections on the machines of people who log in to this vendor's service. They reflect those users' own endpoint hygiene, and a vendor with a large consumer or partner login footprint will always show more of them. Counting that against the vendor would penalise popularity, so this platform does not.
Which of their own systems the exposed credentials open
| System | Times seen |
|---|---|
| https://mail.commvault.com/owa/auth/logon.aspx | 5 |
| https://adfs.commvault.com | 5 |
| https://adfs.commvault.com/adfs/ls | 4 |
| https://sso.commvault.com/Account/Login | 4 |
| https://cloud.commvault.com | 4 |
Classified by the source as: adfs, auth, ftp, owa, sso, vpn.
This is the part a count cannot tell you. A stolen credential for a login page that fronts single sign-on or an administrative console reaches further than the same credential for a marketing site, so it carries the smallest of the three weights in the band above. These are the vendor's own published login pages, nothing private.
Context that is recorded but never scored
Stealer families seen against this domain: Acreed, Remus, Azorult, RedLine, Lumma, CRYPTBOT, Vidar, Raccoon. Which malware took a credential says more about what is circulating than about the vendor, so it is not scored.
Which third-party services appear
| Service | In our directory | Community rating | Occurrences |
|---|---|---|---|
| microsoftonline.com | Not listed | – | 44 |
| csod.com | Not listed | – | 23 |
| concursolutions.com | Not listed | – | 19 |
| network-auth.com | Not listed | – | 18 |
| zoom.us | Not listed | – | 14 |
| salesforce.com | Not listed | – | 14 |
| opentext.com | Not listed | – | 10 |
| amazon.com | Not listed | – | 9 |
| visas-immigration.service.gov.uk | Not listed | – | 9 |
| myprepaidcenter.com | Not listed | – | 9 |
| showpad.biz | Not listed | – | 9 |
| eyemedvisioncare.com | Not listed | – | 8 |
If your own organisation depends on any of these, a successful attack on this vendor and an attack on you share a blast radius. That is worth a question in the security review, not a reason to walk away. Where a service is itself a vendor in our directory it is named and linked, with whatever the community has scored it, so you can read both sides of the dependency in one place. The rating shown is the community's own; it is not derived from this exposure data.
Two independent sources agree on 16 exposed staff credentials.
Source: FireIntel (xti.fireintel.net), public domain summary. Source: Hudson Rock (hudsonrock.com), free infostealer intelligence API. About this data. Read 18 hours ago. DBSE does not collect, hold, or sell this data.
Public vulnerability record
31 CVEs across 5 productsWhat the public CVE catalogue holds against this vendor's products. A higher number here is not a worse vendor, and this is scored into nothing at all.
| Product | Catalogued under | CVEs |
|---|---|---|
| Commvault | Commvault | 17 |
| Commcell | Commvault | 10 |
| Edge server | Commvault | 2 |
| Edge | Commvault | 1 |
| Cortex xsiam commvaultsecurityiq marketplace | Paloaltonetworks | 1 |
Why this is shown and not scored
Counting CVEs punishes the vendors who tell you about them. A company that runs a bug bounty, works with researchers and files CVEs properly will always show more than one that fixes things quietly in a point release. Reading the bigger number as the worse product gets it exactly backwards.
The count also tracks how much software a vendor ships and how long they have shipped it. A vendor with forty products will out-score a vendor with one, whatever either does about security.
And a zero here usually means "not in this catalogue", not "no vulnerabilities found". Absence of a record is not a clean record.
What the list is genuinely good for is specifics: whether the product you are buying appears, and what has been disclosed about it. That is a question for the vendor in a security review, and their answer tells you more than the number does.
Matched in the catalogue as Commvault. Matching is by name, so it can pick up a namesake or miss a brand filed differently.
Source: CVEFeed (cvefeed.io), public CVE catalogue. About this data. Read 16 hours ago. It is not part of the community scorecard, the star rating, or the exposure signal.
Discussions about Commvault
- No threads yet. Start one.