VYPR
Unrated severityNVD Advisory· Published Sep 23, 2021· Updated Sep 17, 2024

CVE-2020-4941

CVE-2020-4941

Description

IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Edge 4.2 discloses sensitive version information in error pages, aiding attackers in further attacks.

Vulnerability

IBM Edge version 4.2 contains an unexpected Content-Type vulnerability that causes the server to reveal sensitive version information in error pages [1]. The issue occurs when a request with an unexpected Content-Type header is sent, triggering an error response that includes internal version details. This information can be used by an attacker to tailor further attacks against the system.

Exploitation

An attacker with low privileges (CVSS PR:L) can send a crafted HTTP request with an unexpected Content-Type header to an IBM Edge 4.2 server [1]. No user interaction is required (UI:N). The server responds with an error page that inadvertently exposes version information, which the attacker can then collect and analyze.

Impact

Successful exploitation results in the disclosure of sensitive version information about the IBM Edge server (confidentiality impact: low) [1]. This information can aid an attacker in identifying specific vulnerabilities or misconfigurations, potentially enabling more targeted attacks. There is no impact on integrity or availability.

Mitigation

IBM has resolved this vulnerability in the latest docker images, which are automatically pulled and deployed from Docker Hub and the IBM Entitled Registry [1]. Users should ensure their IBM Edge 4.2 deployment is updated to the latest available images. No workarounds are available [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.