BMC FootPrints是美国BMC公司的一个IT服务管理与工单跟踪系统。 BMC FootPrints 20.24.01.001及之前版本存在代码问题漏洞,该漏洞源于ASP.NET servlet的VIEWSTATE处理存在不受信任数据反序列化,可能导致经过身份验证的攻击者通过特制序列化对象执行任意代码,完全控制应用程序。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BMC Software, Inc. | FootPrints | 20.20.02≤ 20.24.01.001 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BMC Software, Inc. | FootPrints | 20.20.02 ~ 20.24.01.001 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | BMC FootPrints Asset Core is vulnerable to pre-authentication remote code execution via Java deserialization in the aspnetconfig endpoint. | https://github.com/projectdiscovery/nuclei-templates/blob/main/code/cves/2025/CVE-2025-71260.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-71257 | 7.3 HIGH | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass |
| CVE-2025-71258 | 4.3 MEDIUM | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb |
| CVE-2025-71259 | 4.3 MEDIUM | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSS |
No comments yet