CVE-2025-71257
PoC moderateAuthentication Bypass in BMC FootPrints ITSM REST API and Servlets
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 fail to properly enforce security filters on restricted REST API endpoints and servlets, allowing an authentication bypass (CWE-306). An unauthenticated remote attacker triggers the flaw simply by sending requests to restricted endpoints, with no credentials or user interaction required. Successful exploitation provides unauthorized access to application data and the ability to modify system resources; CVSS 4.0 rates the technical impact as low across confidentiality, integrity, and availability. Public research from watchTowr Labs documents pre-auth attack chains against BMC FootPrints, indicating the bypass can be used as part of a broader exploitation path. No confirmed in-the-wild exploitation or CISA KEV listing yet, but EPSS assigns a 44.6% probability of exploitation within 30 days (99th percentile), making prompt patching advisable.
What to do: Apply the applicable BMC hotfix for your deployed release — 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01 — or upgrade beyond 20.24.01.001. Until patched, restrict network access to the FootPrints web and REST interfaces to trusted networks and review logs for unauthenticated requests hitting restricted endpoints or servlets.
| BMC FootPrints ITSM | 20.20.02 through 20.24.01.001 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and gain unauthorized access to application data and modify system resources. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
- Vendors
- bmc
- Products
- footprints
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X