New Features in service pack 6205

  • AEF-63637 : The Asset Loan feature enables you to mark loanable assets; track asset loaning, return, extension, and expiry; and configure asset loaning notifications.
  • AEF-73176 : Configure a password, for both login and non-login users, to ensure secure access to files, such as exported reports, scheduled reports, and exported request list generated from within the application. Enable File Protection Password under Admin>>Privacy Settings.
  • AEF-31037, AEF-45095, AEF-37001 : User import from Active Directory can now fetch Employee ID and ‘Large Integer’ type field accountExpires.

Issues fixed in service pack 6205

  • AE-72109 :XSS vulnerability found in the asset details page is fixed.
  • AE-72080 :Directory traversal vulnerability found in file upload is fixed.
  • AE-71495 :ZipSlip vulnerability found in distributed asset scan is fixed.
  • AE-72568, 69294 :Vulnerability in deletion of default license types is fixed.
  • AE-68282 :No alert message is displayed, warning about the impacted scan types when we enable “Stop uploading scanned XMLs via non-login URL” under the Security Settings.
  • AE-69108 :Security response headers are missing in the login form.
  • AE-71595 :Vulnerability : Able to create a table and copy data in MSSQL.
  • AE-66826 :Vulnerable HTTP method (OPTIONS) disabled.
  • AE-69292 :Vulnerability of an unauthorized user able to create, edit, and delete currency in the application is fixed
  • AE-71491, 71490 :Failure exception message displayed during network scan is fixed
  • AE-70963 :Purchase Requests with similar vendors are not listed in the Associate PR list when trying to associate a PR with a Purchase Order.
  • AE-71359 :Agent : Option to configure the Agent’s TLS Protocols and Ciphers to secure communications from within the Agent side. Configure it under Admin >> Windows Agent Configuration >> Settings.
Build Release

You may be interested in these other recent articles

29 Jun

Gartner® Magic Quadrant™ Recognising ManageEngine for the 10th time!

29 June 2022 | Nazim Nadir

Gartner® Magic Quadrant™ is a great way to gain objective insights into application performance monitoring (APM) market and its vendors. ManageEngine Applications Manager and site24x7…

Read more
18 Feb

ManageEngine’s IAM and Cybersecurity On-Demand Events Hub

18 February 2022 | Joshua Ball

Watch webinars on demand and listen to podcasts at your convenience. ManageEngine has launched their IAM and Cybersecurity on-demand events hub, a one-stop shop for on-demand webinars and podcasts. At the on-demand events hub, you’ll find:   Carefully curated on-demand webinars from seven unique categories. Over 40 podcast episodes (and counting) on IAM and cybersecurity from three different podcast shows. ​ The webinars and podcasts are regularly updated, so watch this space to ensure you don’t miss out on the latest episodes!​​ Sign up today by clicking here. To find out more…

Read more
8 Sep

ManageEngine positioned in the Gartner® Magic Quadrant™ for ITSM Tools for the second consecutive year

8 September 2021 | Nigel Arnold

The 2021 Gartner® Magic Quadrant™ for IT Service Management Tools is out, and ManageEngine has been included in this year’s report. This is the second…

Read more