BMC FootPrints是美国BMC公司的一个IT服务管理与工单跟踪系统。 BMC FootPrints 20.24.01.001及之前版本存在代码问题漏洞,该漏洞源于externalfeed/RSS API组件存在盲服务端请求伪造,且对外部提供的资源引用验证不足,可能导致经过身份验证的攻击者与内部服务交互或导致资源耗尽,影响可用性。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| BMC Software, Inc. | FootPrints | 20.20.02≤ 20.24.01.001 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| BMC Software, Inc. | FootPrints | 20.20.02 ~ 20.24.01.001 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | BMC FootPrints versions 20.20.02 through 20.24.01.001 contain a Server-Side Request Forgery (SSRF) vulnerability in the /footprints/servicedesk/externalfeed/RSS endpoint. The 'feedUrl' parameter allows unauthenticated attackers to force the server to make HTTP requests to arbitrary URLs, enabling access to internal services and bypassing firewall restrictions. This vulnerability is part of a pre-authenticated RCE chain when combined with CVE-2025-71257 (auth bypass) and CVE-2025-71260 (deserialization). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-71259.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2025-71260 | 8.8 HIGH | BMC FootPrints 代码问题漏洞 |
| CVE-2025-71257 | 7.3 HIGH | BMC FootPrints 访问控制错误漏洞 |
| CVE-2025-71258 | 4.3 MEDIUM | BMC FootPrints 代码问题漏洞 |
暂无评论