IBM
Engineering Workflow Management
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2024-51454 | 22 Jun 2026 | Engineering Workflow Management: 7.0.2 ≤ 7.0.2 Interim Fix 035, 7.0.3 ≤ 7.0.3 Interim Fix 017, 7.1 ≤ 7.1 Interim Fix 004 | Affected Product(s)Version(s)Remediation/Fix/Instructions; IBM Engineering Lifecycle Management - Engineering Workflow Management; 7.0.2Download and install iFix036 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later; 7.0.3Download and install iFix018 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later; 7.1.0Download and install iFix005 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later | Update reference ↗ |
| CVE-2025-33128 | 22 Jun 2026 | Engineering Workflow Management: 7.0.3 ≤ 7.0.3 Interim Fix 020, 7.1.0 ≤ 7.1 Interim Fix 007 | Affected Product(s)Version(s)Remediation/Fix/Instructions; IBM Engineering Lifecycle Management - Engineering Workflow Management; 7.0.3Download and install iFix021 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later; 7.1.0Download and install iFix008 https://www.ibm.com/support/fixcentral/swg/downloadFixes or later | Update reference ↗ |
| CVE-2024-28793 | 28 May 2024 | 7.0.2, 7.0.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-4989 | 15 Mar 2022 | 7.0; 7.0.1; 7.0.2; 6.0.6; 6.0.6.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2021-29701 | 11 Jan 2022 | 7.0; 7.0.1; 7.0.2; 6.0.6; 6.0.6.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-29844 | 27 Oct 2021 | 7.0; 6.0.6; 6.0.6.1; 7.0.1; 7.0.2; 6.0.2 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2021-20507 | 19 Jul 2021 | 7.0; 7.0.1; 7.0.2; 6.0.6; 6.0.6.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-5031 | 19 Jul 2021 | 7.0; 7.0.1; 7.0.2; 6.0.6; 6.0.6.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-20520 | 30 Mar 2021 | 7.0; 7.0.1; 7.0.2; 6.0.2; 6.0.6; 6.0.6.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2021-20503 | 30 Mar 2021 | 7.0; 7.0.1; 7.0.2; 6.0.2; 6.0.6; 6.0.6.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2021-20352 | 30 Mar 2021 | 7.0; 7.0.1; 7.0.2; 6.0.2; 6.0.6; 6.0.6.1 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-4866 | 4 Mar 2021 | 7.0; 7.0.1; 7.0.2; 6.0.2; 6.0.6; 6.0.6.1; 7.0.0 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-4547 | 27 Jan 2021 | 7.0; 7.0.2; 6.0.6; 6.0.6.1; 6.0.2; 7.0.0 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-4544 | 8 Jan 2021 | 7.0; 7.0.1; 6.0.2; 6.0.6; 6.0.6.1; 7.0.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-4546 | 2 Sep 2020 | 7.0; 6.0.2; 6.0.6; 6.0.6.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.