---
id: CVE-2024-51454
title: >-
  IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3
  through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is
  vulnerable to HTTP header injection, caused by improper validation of input by
  the HOST …
summary: >-
  IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3
  through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is
  vulnerable to HTTP header injection, caused by improper validation of input by
  the HOST …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-644
vendor: ibm
product: engineering_workflow_management
affected:
  - engineering_workflow_management = 7.0.2
  - engineering_workflow_management = 7.0.3
  - engineering_workflow_management = 7.1.0
published: '2026-06-22'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-51454'
references:
  - url: 'https://www.ibm.com/support/pages/node/7276371'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00253
epssPercentile: 0.15177
ingestedAt: '2026-10-02T01:05:54.725Z'
---

## Overview

IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

## Affected

- `engineering_workflow_management = 7.0.2`
- `engineering_workflow_management = 7.0.3`
- `engineering_workflow_management = 7.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
