Executive brief
BMC FootPrints is an IT Service Management platform used by organizations to manage service requests, incidents, and assets. This vulnerability allows authenticated attackers to force the FootPrints server to make arbitrary outbound network requests, potentially enabling attackers to scan internal networks or interact with internal services that should not be accessible from the internet.
Technical details
CVE-2025-71258 is a blind server-side request forgery (SSRF) vulnerability in the searchWeb API component of BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001. The vulnerability stems from improper URL validation that allows attackers to manipulate the API to initiate arbitrary outbound requests from the server. Authentication is required to exploit this vulnerability, and the attack vector is network-based. An attacker can leverage this SSRF to perform reconnaissance of internal network services, interact with internal APIs, or probe infrastructure availability. BMC has released hotfixes for multiple affected versions (20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01) as of September 2, 2025.
Affected products
- BMC FootPrints ITSM 20.20.02 through 20.24.01.001
Timeline
- 2025-06-06: disclosed: watchTowr discloses CVE-2025-71258 (WT-2025-0070) to BMC
- 2025-09-02: patched: BMC releases hotfixes for affected versions
- 2026-03-02: advisory: CVE-2025-71258 assigned
- 2026-03-18: other: watchTowr publishes detailed research blog post