CVE-2024-51454: IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Other sources
IBM Engineering Workflow Management is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Engineering Lifecycle Management - Engineering Workflow Managementto a version that resolves this vulnerability.Fixed in 7.0.2Patch iFix036 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Engineering Workflow Managementto a version that resolves this vulnerability.Fixed in 7.0.3Patch iFix018 - Upgrade
Upgrade
IBM Engineering Lifecycle Management - Engineering Workflow Managementto a version that resolves this vulnerability.Fixed in 7.1.0Patch iFix005
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51454?
The severity of CVE-2024-51454 is rated as medium with a score of 6.5.
How do I fix CVE-2024-51454?
To fix CVE-2024-51454, ensure to update IBM Engineering Workflow Management to a version that includes the latest interim fix addressing the vulnerability.
What is CVE-2024-51454?
CVE-2024-51454 is a vulnerability in IBM Engineering Workflow Management that allows for HTTP header injection due to improper validation of HOST headers.
What versions are affected by CVE-2024-51454?
CVE-2024-51454 affects IBM Engineering Workflow Management versions 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004.
What impact does CVE-2024-51454 have on systems?
CVE-2024-51454 can allow an attacker to conduct various attacks by exploiting the HTTP header injection vulnerability.