THREAT OPS › Threat News › [NVD] CVE-2025-71258 (MEDIUM 4.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL
[NVD] CVE-2025-71258 (MEDIUM 4.3) — BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL
CVE-2025-71258 CVSS: 4.3 MEDIUM Published: 2026-03-19T14:16:13.180
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL validation to perform internal network scanning or i
Indicators of compromise
- CVE-2025-71258cve
- 20.24.01.001ipv4
- 20.20.03.002ipv4
- 20.21.01.001ipv4
- 20.21.02.002ipv4
- 20.22.01.001ipv4
- 20.23.01.002ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-71258