# BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + Java Deserialization (CVE-2025-71257/71258/71259/71260)

> watchTowr Labs disclosed a four-vulnerability exploit chain in BMC FootPrints ITSM (v20.20.02-20.24.01.001) that lets an unauthenticated attacker abuse the password-reset endpoint to obtain a guest SEC_TOKEN, pivot through two SSRF endpoints, and reach an insecure Java deserialization sink in the Mono-based ASP.NET VIEWSTATE handler to write a JSP web shell and gain RCE as LOCAL SERVICE. BMC shipped hotfixes in September 2025; CVEs were assigned March 2026 and disclosed publicly March 18, 2026 with a working Python PoC.

- **Published:** 2026-03-18T00:00:00Z
- **Last reviewed:** 2026-03-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1516
- **ID:** TL-2026-1516
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-71260

## Description

BMC FootPrints ITSM is an on-premises IT service management / help-desk platform. watchTowr Labs identified that the application's Spring Security filter chain contains an exception for the `/passwordreset/request/` endpoint: a custom `GenericGuestAuthenticationFilter` (backed by `PasswordResetRequestAuthenticationFilter`) calls `applyGuestForThisRequest()` before the standard `isAuthenticated()` check, and under qualifying conditions issues a valid opaque `SEC_TOKEN` session cookie (e.g. `87x0EkX5BFHyWaktfxK5gasnc_LfwWtYsCm5yIorFuwaexEtaK`) to an unauthenticated caller (CVE-2025-71257/WT-2025-0069, CWE-306, missing authentication for critical function). watchTowr reached this finding by systematically enumerating the 58 security-filter regex patterns defined in `deployment/non-version-specific/conf/footprints-application-beans.xml`, extracting `web.xml` and decompiling `.class` files to fingerprint which endpoints the filter chain treats as pre-authenticated.

That guest-authenticated `SEC_TOKEN` cookie is sufficient to reach two further endpoints that perform blind server-side request forgery: `/import/searchWeb?url=` (CVE-2025-71258/WT-2025-0070, `dataEncoding` parameter also accepted) and `/externalfeed/RSS?feedUrl=` (CVE-2025-71259/WT-2025-0071), both of which accept attacker-controlled URLs with no allow-listing or destination validation and confirm out-of-band via callback rather than response content — functioning as an internal-network proxy primitive attackers can use to reach otherwise unreachable internal services.

The critical link in the chain is CVE-2025-71260/WT-2025-0072 (CWE-502, deserialization of untrusted data, CVSS 3.1 8.8), rooted in FootPrints' use of Mono (an open-source .NET runtime implemented in Java) to host ASP.NET-style configuration pages. The `/aspnetconfig/` endpoint (routed through `VmwDynamicServlet` -> `GhDynamicHttpServlet`) accepts a `__VIEWSTATE` parameter that is Base64-decoded (serialized Java objects begin with the recognizable `rO0AB` prefix) and passed directly through `getRequestParameterMap()` -> `get_Form()` -> `ObjectInputStream.readObject()` inside `Mainsoft/Web/Hosting/BaseFacesStateManager.class` with no type filtering. watchTowr found that the parameter is only parsed by the framework when the request Content-Type is `multipart/form-data` (or, alternatively, a GET with a dummy `__VIEWSTATE` plus an `application/x-www-form-urlencoded` body) — a query-string-only VIEWSTATE resolves to null and is not exploitable. Using `ysoserial`'s `AspectJWeaver` gadget (`java -jar ysoserial.jar AspectJWeaver "filename.jsp;BASE64TEXT" | base64`, backed by vulnerable `aspectjweaver-1.9.2` and `commons-collections-3.2.2` on the classpath, gadget attributed to researcher "Jang"), the deserialization is coerced into an arbitrary file write with path-traversal support in the filename parameter, dropping a JSP web shell (e.g., `watchTowr.jsp` in the published PoC, or a randomized filename such as `MNdeu12Wf.jsp` for detection evasion) into the Tomcat web root (`webapps/ROOT/`, under the FootPrints install path `C:\Program Files\BMC Software\FootPrints\web`). Invoking the shell confirms code execution as the `LOCAL SERVICE` account with a working directory under `C:\Program Files\Apache Software Foundation\Tomcat 9.0`; the injected JSP retrieves `user.name` and `user.dir` Java system properties as an immediate post-exploitation discovery step, and file execution requires no separate compilation step since Tomcat interprets JSP directly.

watchTowr additionally notes the Mono/.NET-in-Java implementation detail as an incidental defense-evasion factor: the `__VIEWSTATE` parameter name is conventionally associated with ASP.NET applications, which can mislead defenders and static analysis tooling into treating the deserialization sink as a .NET-specific ViewState issue rather than a Java `ObjectInputStream` vulnerability, and the component's minimal prior CVE history (last CVE in 2014) suggests it received comparatively little security scrutiny prior to this research.

The full chain — guest-token auth bypass -> SSRF-capable pivot -> reach the deserialization sink -> AspectJWeaver gadget -> JSP web shell -> RCE — requires zero credentials and zero user interaction. watchTowr reported all four issues to BMC on 2025-06-06; BMC confirmed reproduction of the RCE on 2025-09-02 and shipped hotfixed builds for every affected release train. CVEs were formally assigned 2026-03-02 and the technical write-up, including a public Python PoC and GitHub repository, was released 2026-03-18.

## MITRE ATT&CK

- T1592.002 Software
- T1588.005 Exploits
- T1588.006 Vulnerabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505.003 Web Shell
- T1027 Obfuscated Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1005 Data from Local System
- T1090.004 Domain Fronting

## Sources

- [Thanks ITSM: Threat Actors Have Never Been So Organized (BMC FootPrints Pre-Auth Remote Code Execution Chains)](https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains/)
- [watchTowr-vs-BMC-Footprints-RCE PoC repository](https://github.com/watchtowrlabs/watchTowr-vs-BMC-Footprints-RCE-CVE-2025-71257-CVE-2025-71260)
- [NVD - CVE-2025-71257](https://nvd.nist.gov/vuln/detail/CVE-2025-71257)
- [NVD - CVE-2025-71260](https://nvd.nist.gov/vuln/detail/CVE-2025-71260)
- [VulnCheck Advisory - BMC FootPrints ITSM Authentication Bypass](https://www.vulncheck.com/advisories/bmc-footprints-itsm-authentication-bypass)
- [VulnCheck Advisory - BMC FootPrints ITSM VIEWSTATE Deserialization RCE](https://www.vulncheck.com/advisories/bmc-footprints-itsm-viewstate-deserialization-rce)
- [BMC FootPrints Release Notes - 2024 Release 01 Patch 2](https://docs.bmc.com/xwiki/bin/view/More-Products/Footprints/FootPrints/fp2024/Release-notes/2024-Release-01-Patch-2/)
- [CVE-2025-71259: BMC FootPrints ITSM SSRF Vulnerability](https://www.sentinelone.com/vulnerability-database/cve-2025-71259/)
- [CVE-2025-71258 | THREATINT](https://cve.threatint.eu/CVE/CVE-2025-71258)
- [ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More](https://thehackernews.com/2026/03/threatsday-bulletin-fortigate-raas.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1516
