VulnSea

bmc has 8 CVEs on record between 2021 and 2026. The busiest recent month was March 2026 with 4. The median CVSS is 6.7 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-918 (3). Most affected products: footprints (4), remedy_mid-tier (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.7
Publish → KEV
Last 90 days
0 prev 0

Products

  • footprints 4
  • remedy_mid-tier 4
8
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

bmc vulnerabilities

CVEs affecting bmc, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2025-71260High· 8.8
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can…

Twilightbmc · footprintsEPSS 34%via NVD
CVE-2025-71259Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from th…

Twilightbmc · footprintsEPSS 13%via NVD
CVE-2025-71258Medium· 4.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound re…

Twilightbmc · footprintsEPSS 17%via NVD
CVE-2025-71257High· 7.3PoC
6mo ago

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can…

Midnightbmc · footprintsEPSS 45%via NVD
CVE-2017-17678Medium· 6.1
5y ago

BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS)

BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utility.

Sunlitbmc · remedy_mid-tierEPSS 0.59%via NVD
CVE-2017-17675Medium· 5.3
5y ago

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

Sunlitbmc · remedy_mid-tierEPSS 0.87%via NVD
CVE-2017-17677High· 8.8
5y ago

BMC Remedy 9.1SP3 is affected by authenticated code execution

BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.

Twilightbmc · remedy_mid-tierEPSS 1.1%via NVD
CVE-2017-17674Critical· 9.8
5y ago

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Sid…

Midnightbmc · remedy_mid-tierEPSS 2.1%via NVD
bmc vulnerabilities (CVEs) · VulnSea