ZeroHour

CVE-2025-71257

PoC moderate

Authentication Bypass in BMC FootPrints ITSM REST API and Servlets

CVSS 4.0
6.9 medium
EPSS
45%p99
Published
()
Modified
AI analysis

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 fail to properly enforce security filters on restricted REST API endpoints and servlets, allowing an authentication bypass (CWE-306). An unauthenticated remote attacker triggers the flaw simply by sending requests to restricted endpoints, with no credentials or user interaction required. Successful exploitation provides unauthorized access to application data and the ability to modify system resources; CVSS 4.0 rates the technical impact as low across confidentiality, integrity, and availability. Public research from watchTowr Labs documents pre-auth attack chains against BMC FootPrints, indicating the bypass can be used as part of a broader exploitation path. No confirmed in-the-wild exploitation or CISA KEV listing yet, but EPSS assigns a 44.6% probability of exploitation within 30 days (99th percentile), making prompt patching advisable.

What to do: Apply the applicable BMC hotfix for your deployed release — 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01 — or upgrade beyond 20.24.01.001. Until patched, restrict network access to the FootPrints web and REST interfaces to trusted networks and review logs for unauthenticated requests hitting restricted endpoints or servlets.

Affected
BMC FootPrints ITSM20.20.02 through 20.24.01.001
Estimated exposure
moderateon the order of thousands of organizational deployments (tens of thousands of ITSM users), with likely only a fraction exposed to the internet — BMC FootPrints is a long-standing on-premises mid-market/enterprise ITSM product whose installed base is plausibly in the thousands of organizations rather than millions, and most ITSM instances are deployed internally rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and gain unauthorized access to application data and modify system resources. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Vendors
bmc
Products
footprints
Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news