CVE-2025-71258: BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or interact with internal services, impacting system availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Fixed in 20.20.02 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Patch 20.20.03.002 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Patch 20.21.01.001 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Patch 20.21.02.002 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Fixed in 20.22.01 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Patch 20.22.01.001 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Fixed in 20.23.01 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Patch 20.23.01.002 - Upgrade
Upgrade
BMC FootPrints ITSM (searchWeb API)to a version that resolves this vulnerability.Fixed in 20.24.01
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71258?
CVE-2025-71258 is classified as a medium severity vulnerability due to its potential for exploitation by authenticated attackers.
How do I fix CVE-2025-71258?
To fix CVE-2025-71258, upgrade BMC FootPrints ITSM to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-71258?
CVE-2025-71258 affects BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001.
What does CVE-2025-71258 allow an attacker to do?
CVE-2025-71258 allows authenticated attackers to initiate arbitrary outbound requests from the server, leading to possible information disclosure.
Is CVE-2025-71258 a client-side or server-side vulnerability?
CVE-2025-71258 is a server-side vulnerability, specifically a blind server-side request forgery (SSRF).