---
id: CVE-2025-71258
title: >-
  BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind
  server-side request forgery vulnerability in the searchWeb API component that
  allows authenticated attackers to cause the server to initiate arbitrary
  outbound re…
summary: >-
  BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind
  server-side request forgery vulnerability in the searchWeb API component that
  allows authenticated attackers to cause the server to initiate arbitrary
  outbound re…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
vendor: bmc
product: footprints
affected:
  - 'footprints >= 20.20.02, <= 20.24.01.001'
published: '2026-03-19'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71258'
references:
  - url: >-
      https://docs.bmc.com/xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/Release-notes/2024-Release-01-Patch-2/
    label: disclosure@vulncheck.com
  - url: >-
      https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/bmc-footprints-itsm-blind-ssrf-in-searchweb
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
epss: 0.1743
epssPercentile: 0.97028
ingestedAt: '2026-08-06T15:59:59.304Z'
exploits:
  nuclei:
    - CVE-2025-71258
  checkedAt: '2026-09-27T10:33:37.157Z'
exploitAvailable: true
---

## Overview

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or interact with internal services, impacting system availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

## Affected

- `footprints >= 20.20.02, <= 20.24.01.001`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
