This document addresses a open redirection vulnerability identified in ManageEngine Remote Access Plus, reported by Lukasz.
Update Released Build: 10.1.2137.6
Update Released Date: December 16, 2021
In specific cases, an unauthenticated user can provide the product technician a link that can redirect the technician to a different URL.
From now on, the URLs involved are validated before redirecting the technician.
Please upgrade to the latest build 10.1.2137.6 as normally done. You can visit our service packs page and download the latest build. Alternatively, you can also follow the below steps:
Note: This vulnerability is not applicable for Remote Access Plus Cloud.
For any further queries on this, please reach out to Remote Access Plus support at remoteaccessplus-support@manageengine.com.