ManageEngine Exchange Reporter Plus Regular Expression Denial-of-Service Vulnerability

Vulnerability

A regular expression denial-of-service (ReDoS) vulnerability has been identified in ManageEngine Exchange Reporter Plus versions through 5721. This vulnerability resides in the search module, where the regular expression processing can be exploited to degrade performance and disrupt normal operations.

Impact

Exploitation of this vulnerability could lead to a denial-of-service condition, where authenticated users experience significant delays or interruptions in the search functionality of the Content Search module.

Remediation

Users are advised to update Exchange Reporter Plus to version 5722 or later. The latest service pack can be downloaded from the ManageEngine Exchange Reporter Plus service pack page. For assistance with the update, contact ManageEngine product support at support@exchangereporterplus.com.

Added: Oct 30, 2025, 3:59 PM
Updated: Oct 30, 2025, 3:59 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
4.9
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.