CVE-2025-71257

7.3

BMC Software · FootPrints

BMC FootPrints ITSM contains an authentication bypass vulnerability in restricted REST API endpoints and servlets, allowing unauthenticated remote attackers to access sensitive application data.

Executive summary

An authentication bypass vulnerability in BMC FootPrints allows unauthenticated remote attackers to access restricted application data and modify system resources.

Vulnerability

This is an authentication bypass flaw (CWE-306) caused by improper enforcement of security filters on specific REST API endpoints and servlets. The vulnerability allows an unauthenticated remote attacker to interact with restricted functionality that should otherwise require active session authentication.

Business impact

Successful exploitation grants an unauthorized actor the ability to interact with the ITSM platform, which typically contains sensitive organizational data, incident reports, and IT configuration details. Because the vulnerability allows for the modification of system resources, it poses a significant risk to the integrity of internal IT management processes and may facilitate further lateral movement or data exfiltration. The CVSS score of 7.3 reflects the high severity of bypassing security controls in a centralized management application.

Remediation

Immediate Action: Administrators must apply the relevant vendor hotfix immediately. Supported versions requiring patches include 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Proactive Monitoring: Review web server and application access logs for anomalous requests directed at REST API endpoints or unusual patterns of interaction from non-authenticated sources.

Compensating Controls: Implement strict network access control lists to restrict access to the FootPrints web interface to trusted IP ranges only, and deploy Web Application Firewall (WAF) rules designed to detect and block unauthorized attempts to access restricted API paths.

Exploitation status

Public Exploit Available: Yes, a technical research write-up detailing the exploit chain and a proof-of-concept exists (attributed to watchTowr Labs).

Analyst recommendation

Given the central role ITSM platforms play in IT operations and the presence of a published proof-of-concept, this vulnerability represents a significant security risk. Organizations should prioritize patching their BMC FootPrints instances using the vendor-provided hotfixes listed above to eliminate the authentication bypass vector and prevent potential unauthorized system manipulation.

More BMC Software CVEs

Sources

Originally found and disclosed by Sonny of watchTowr, per the CVE Program record.