CVE-2020-4941
Description
IBM Edge 4.2 could reveal sensitive version information about the server from error pages that could aid an attacker in further attacks against the system. IBM X-Force ID: 191941.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM Edge 4.2 discloses sensitive version information in error pages, aiding attackers in further attacks.
Vulnerability
IBM Edge version 4.2 contains an unexpected Content-Type vulnerability that causes the server to reveal sensitive version information in error pages [1]. The issue occurs when a request with an unexpected Content-Type header is sent, triggering an error response that includes internal version details. This information can be used by an attacker to tailor further attacks against the system.
Exploitation
An attacker with low privileges (CVSS PR:L) can send a crafted HTTP request with an unexpected Content-Type header to an IBM Edge 4.2 server [1]. No user interaction is required (UI:N). The server responds with an error page that inadvertently exposes version information, which the attacker can then collect and analyze.
Impact
Successful exploitation results in the disclosure of sensitive version information about the IBM Edge server (confidentiality impact: low) [1]. This information can aid an attacker in identifying specific vulnerabilities or misconfigurations, potentially enabling more targeted attacks. There is no impact on integrity or availability.
Mitigation
IBM has resolved this vulnerability in the latest docker images, which are automatically pulled and deployed from Docker Hub and the IBM Entitled Registry [1]. Users should ensure their IBM Edge 4.2 deployment is updated to the latest available images. No workarounds are available [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- IBM/Edgev5Range: 4.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/191941mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6491627mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.