S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 20, 2026

CVE-2025-71259 Scanner

CVE-2025-71259 Scanner - Server-Side Request Forgery (SSRF) vulnerability in BMC FootPrints

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-71259
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit insufficient validation of externally supplied resource references to interact with internal services or cause resource exhaustion impacting availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
FootPrintsby BMC Software, Inc.
20.20.02
Updated Aug 19, 2026View on NVD →
Detail

BMC FootPrints is commonly used by IT departments and organizations for managing service desk requests, incidents, and changes within IT services. This platform aids various businesses in handling both internal and external service operations efficiently. It's prominent in sectors requiring robust IT service management solutions, such as healthcare, finance, and education. Administrators and IT professionals utilize FootPrints to streamline service desk operations and improve customer satisfaction. The software is intended to enhance the effectiveness of service management by integrating various tools and automation. Additionally, it's designed to facilitate compliance with ITIL standards and improve management's visibility into IT performance.

The vulnerability detected in BMC FootPrints is a Server-Side Request Forgery (SSRF) flaw. SSRF vulnerabilities occur when an attacker tricks a server into initiating requests to unintended locations. In this instance, unauthenticated attackers can leverage the 'feedUrl' parameter to make HTTP requests via the server to arbitrary URLs. Consequently, this can lead to unauthorized access to internal services, and potentially circumvent firewall protections. The vulnerability is serious, as it's part of a pre-authenticated RCE chain in conjunction with other CVEs. It highlights a critical gap in managing how external requests are handled by the server.

Technically, the issue lies within the /footprints/servicedesk/externalfeed/RSS endpoint of BMC FootPrints. The server processes the 'feedUrl' parameter without sufficient validation, allowing arbitrary external requests. This could enable attackers to interact with otherwise unreachable network resources by controlling the server's outgoing requests. This SSRF vulnerability could be exploited to gather sensitive internal data or use the server as a pivot for further network penetration. The risk is elevated when combined with other vulnerabilities to execute more potent attacks.

The possible effects of exploiting this SSRF vulnerability include unauthorized network scanning and possible retrieval of sensitive information from internal resources. Malicious actors could potentially map the internal network, gain access to protected services, or exfiltrate data through manipulated server requests. Moreover, exploiting SSRF can facilitate further attacks such as Remote Code Execution (RCE) when combined with other vulnerabilities. Organizations can face significant security breaches and data loss if this vulnerability is left unmitigated.

REFERENCES

Solution Advice
  • Implement input validation and sanitization to ensure only safe URLs can be processed by the 'feedUrl' parameter.
  • Update BMC FootPrints to the latest version which includes the patch for this vulnerability.
  • Apply server-side request filtering to block unwanted external traffic.
  • Continuously monitor and audit the service to detect any abnormal behaviors.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.