Executive brief
IBM Engineering Workflow Management, a tool used by software teams to manage tasks and source code, is vulnerable to a security flaw where it incorrectly handles web request headers. An attacker could exploit this to redirect users to malicious sites, steal login sessions, or corrupt the data stored in the system's temporary web cache. This could lead to unauthorized access to project data or the disruption of development operations.
Technical details
IBM Engineering Workflow Management is vulnerable to HTTP header injection (CWE-644) due to improper validation of input within the HTTP HOST header. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the server. Successful exploitation could allow the attacker to perform various attacks, including cache poisoning, session hijacking, or cross-site scripting (XSS) by injecting malicious headers into the application's response. The vulnerability affects versions 7.0.2, 7.0.3, and 7.1.0, and has been addressed in subsequent interim fixes (iFix036, iFix018, and iFix005 respectively).
Affected products
- IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, 7.1 through 7.1 Interim Fix 004
Timeline
- 2026-06-19: advisory: Initial publication by IBM
- 2026-06-22: disclosed: NVD publication date