CVE-2025-71260 PUBLISHED

BMC 20.20.02 <= 20.24.01.001 FootPrints ITSM VIEWSTATE Deserialization RCE

Assigner: VulnCheck
Reserved: 02.03.2026 Published: 19.03.2026 Updated: 19.03.2026

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor BMC Software, Inc.
Product FootPrints
Versions Default: unaffected
  • affected from 20.20.02 to 20.24.01.001 (incl.)

Credits

  • Sonny of watchTowr finder

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE