Impact
The vulnerability arises from insufficient enforcement of security filters on restricted REST API endpoints and servlets, allowing unauthenticated remote attackers to bypass authentication and invoke privileged functions. This flaw permits attackers to read and modify application data and system resources, thereby compromising confidentiality, integrity, and availability. The weakness is identified as a CWE-306 (Authentication Bypass).
Affected Systems
BMC Software’s FootPrints ITSM, versions 20.20.02 through 20.24.01.001, are affected. The vendor has released hotfixes for these versions, which include 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
Risk and Exploitability
The CVSS v3.1 score of 6.9 indicates Medium severity, while an EPSS score of 12% suggests a non‑negligible chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote; an attacker can send unauthenticated requests to protected REST endpoints to bypass access controls.
OpenCVE Enrichment