Executive brief
BMC FootPrints is an IT Service Management platform used by organizations to manage service requests, incidents, and assets. An authentication bypass vulnerability allows unauthenticated remote attackers to invoke restricted functionality, access sensitive application data, and modify system resources without credentials—potentially enabling unauthorized ticket manipulation, configuration changes, and data theft from a centralized IT management system.
Technical details
The vulnerability stems from improper enforcement of security filters on restricted REST API endpoints and servlets in BMC FootPrints versions 20.20.02 through 20.24.01.001. The root cause is inadequate access control validation, allowing unauthenticated remote attackers to bypass authentication mechanisms over the network. An attacker can invoke restricted API endpoints to read sensitive data, modify system resources, and chain this vulnerability with other flaws (such as deserialization issues) to achieve pre-authenticated remote code execution. BMC has released hotfixes for versions 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
Affected products
- BMC FootPrints ITSM 20.20.02 through 20.24.01.001
Timeline
- 2026-03-02: disclosed: CVE assigned
- 2026-03-18: disclosed: watchTowr Labs research published
- 2025-06-06: other: watchTowr discloses vulnerability to BMC
- 2025-09-02: patched: BMC releases hotfixes for affected versions