IBM Lotus Expeditor contains a flaw that is triggered due to the program not properly perform access controls during the parsing of header requests. With a specially crafted header, an attacker may potentially be able to spoof the origin of a localhost request.
Upgrade to version 6.2 FP5 (Fix Pack 5) + Security Pack or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.