← volver
CVE-2025-71258

BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWeb

CVSS 5.3 MEDIUMEPSS 17.4%CWE-918
Vexday Risk Score
33Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 5.3EPSS 17.4%KEV nãoPoC Nuclei simMetasploit Patch referenciado
Ciclo de vida
19 mar 2026Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or interact with internal services, impacting system availability. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →