CVE-2024-51454
Undergoing Analysis Undergoing Analysis - In Progress
HTTP Header Injection in IBM Engineering Workflow Management

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: IBM Corporation

Description
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
ibm engineering_workflow_management to 7.0.2 (inc)
ibm engineering_workflow_management to 7.0.3 (inc)
ibm engineering_workflow_management to 7.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-644 The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2024-51454 is a vulnerability in IBM Engineering Workflow Management caused by improper validation of input in the HOST headers, leading to HTTP header injection.

This flaw allows attackers to perform various malicious activities such as cross-site scripting, cache poisoning, or session hijacking.

It affects versions 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 of IBM Engineering Workflow Management.

Impact Analysis

This vulnerability can impact you by allowing attackers to exploit the system through HTTP header injection.

  • Cross-site scripting attacks that can compromise user sessions or steal sensitive information.
  • Cache poisoning which can lead to serving malicious content to users.
  • Session hijacking that can allow attackers to take over user sessions and gain unauthorized access.
Mitigation Strategies

To mitigate the CVE-2024-51454 vulnerability in IBM Engineering Workflow Management, you should apply the appropriate interim fixes released by IBM.

  • For version 7.0.2, apply iFix036 or later.
  • For version 7.0.3, apply iFix018 or later.
  • For version 7.1.0, apply iFix005 or later.

No workarounds are currently available, so applying these fixes is the recommended immediate action.

Compliance Impact

The provided information does not specify how the CVE-2024-51454 vulnerability affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-51454. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart