S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 20, 2026

CVE-2025-71258 Scanner

CVE-2025-71258 Scanner - Server-Side-Request-Forgery (SSRF) vulnerability in BMC FootPrints

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-71258
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or interact with internal services, impacting system availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
FootPrintsby BMC Software, Inc.
20.20.02
Updated Sep 9, 2026View on NVD →
Detail

BMC FootPrints is a popular service desk and customer service management software that is often used by businesses to streamline customer service operations. IT departments and helpdesk teams rely on it to manage, track, and report on customer service requests and issues. The software is designed to improve efficiency by automating workflows and providing a centralized hub for information management. It is widely used in enterprises to facilitate multi-departmental collaboration. The use of BMC FootPrints can enhance customer satisfaction by ensuring timely responses to service requests. Overall, BMC FootPrints supports the efficient and secure management of service requests across a variety of industries.

The detected vulnerability is a Server-Side Request Forgery (SSRF) that allows unauthenticated attackers to exploit the /footprints/servicedesk/import/searchWeb endpoint. By leveraging the vulnerability, attackers can force the server to make HTTP requests to arbitrary URLs. This compromises internal services, bypassing firewall restrictions. This SSRF is part of a broader pre-authenticated remote code execution chain. The chain involves combining this SSRF vulnerability with others such as authentication bypass and deserialization vulnerabilities. It represents a critical risk as it provides an avenue for further exploitation.

Technical details of the vulnerability revolve around the 'url' parameter used in the /footprints/servicedesk/import/searchWeb endpoint. This parameter allows sending arbitrary requests from the server side which an attacker can manipulate. Due to inadequate validation, the server processes attacker-supplied input without restriction, executing requests to internal or external endpoints. This oversight in URL validation is further exploitable when combined with additional vulnerabilities such as CVE-2025-71257 and CVE-2025-71260. The vulnerability allows for complex attack chains leading to significant risks if unpatched. The endpoint thus acts as a gateway for potential unauthorized access.

When exploited, the vulnerability can lead to multiple adverse effects affecting the target system and network. Attackers may gain unauthorized access to sensitive data housed within the internal network by bypassing protective firewalls. There is a potential degradation of system availability if the SSRF facilitates a denial of service by overloading network resources. Moreover, the ability of attackers to interact with internal services can lead to the extraction of confidential information or unauthorized adjustments in service configurations. These consequences necessitate the prioritization of mitigation strategies to safeguard affected systems.

REFERENCES

Solution Advice
  • Apply the hotfixes released by BMC on September 2, 2025, for all affected branches.
  • Update to the latest patched version of BMC FootPrints.
  • Implement strict input validation and sanitization techniques on the 'url' parameter to prevent SSRF attacks.
  • Utilize firewall rules to prevent unauthorized outbound requests from the server.
  • Monitor network traffic for suspicious patterns indicative of compromise or exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.