Executive brief
BMC FootPrints is an IT Service Management platform used by organizations to manage service requests, incidents, and IT assets. A blind server-side request forgery vulnerability in the RSS feed component allows authenticated users to trigger arbitrary outbound network requests from the server, potentially exposing internal services or causing service disruption through resource exhaustion.
Technical details
This is a blind server-side request forgery (SSRF) vulnerability in the externalfeed/RSS API component of BMC FootPrints ITSM. The vulnerability stems from insufficient validation of externally supplied resource references, allowing authenticated attackers to craft requests that force the server to make arbitrary outbound HTTP requests. An attacker with valid credentials can exploit this to interact with internal services, bypass firewalls, or trigger denial-of-service conditions through resource exhaustion. The vulnerability affects versions 20.20.02 through 20.24.01.001, and patches have been released for affected versions.
Affected products
- BMC FootPrints ITSM 20.20.02 through 20.24.01.001
Timeline
- 2026-03-18: disclosed: watchTowr publishes research on CVE-2025-71259 and related vulnerabilities
- 2025-09-02: patched: BMC releases hotfixes for versions 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01
- 2026-03-02: advisory: CVE-2025-71259 assigned by NVD