CVE-2025-71260

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote code execution and fully compromise the application. The following hotfixes remediate the vulnerability: 20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, and 20.24.01.
Configurations

No configuration.

History

19 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 14:16

Updated : 2026-03-20 13:39


NVD link : CVE-2025-71260

Mitre link : CVE-2025-71260

CVE.ORG link : CVE-2025-71260


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data