Impact
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain unauthorized access to application data and system resources. The attacker can exploit the lack of proper security filter enforcement on restricted REST API endpoints and servlets. This is a CWE‑306 (Authentication Bypass) weakness that exposes sensitive data and allows modification of system resources.
Affected Systems
FootPrints ITSM from BMC Software, Inc. versions 20.20.02 through 20.24.01.001
Risk and Exploitability
The CVSS v3.1 score is 6.9 indicating medium severity. EPSS score is not available and it is not listed in the KEV catalog. The vulnerability is exploitable remotely by unauthenticated attackers who can issue requests to restricted REST endpoints. The attack path does not require user interaction and could allow full control over data within the application.
OpenCVE Enrichment