Junglewise Threat Intelligence

CVE-2024-51454: IBM Engineering Workflow Management HTTP header injection

CVE-2024-51454 · Severity: medium · CVSS 6.5 · Published 2026-06-22

Vendors: IBM.

Executive brief

IBM Engineering Workflow Management, a tool used by software teams to manage tasks and source code, is vulnerable to a security flaw where it incorrectly handles web request headers. An attacker could exploit this to redirect users to malicious sites, steal login sessions, or corrupt the data stored in the system's temporary web cache. This could lead to unauthorized access to project data or the disruption of development operations.

Technical details

IBM Engineering Workflow Management is vulnerable to HTTP header injection (CWE-644) due to improper validation of input within the HTTP HOST header. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the server. Successful exploitation could allow the attacker to perform various attacks, including cache poisoning, session hijacking, or cross-site scripting (XSS) by injecting malicious headers into the application's response. The vulnerability affects versions 7.0.2, 7.0.3, and 7.1.0, and has been addressed in subsequent interim fixes (iFix036, iFix018, and iFix005 respectively).

Affected products

  • IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, 7.1 through 7.1 Interim Fix 004

Timeline

  • 2026-06-19: advisory: Initial publication by IBM
  • 2026-06-22: disclosed: NVD publication date

References

Related threats