Are any ManageEngine products (like ServicedeskPlus) vulnerable to recent "Ghostcat" exploit?

Are any ManageEngine products (like ServicedeskPlus) vulnerable to recent "Ghostcat" exploit?

i see referenced in this previous post

https://pitstop.manageengine.com/portal/community/topic/java-standalone-application-any-servler-container-like-apache-tomcat-behind

that some manageengine products are based on Apache Tomcat. given the most recent "ghostcat" exploit that was discovered, what is the eta for updates to use a version of tomcat which has this patched?

Exploit details:

https://www.cisecurity.org/advisory/a-vulnerability-in-apache-tomcat-could-allow-for-arbitrary-file-reading-cve-2020-1938_2020-028/

Detailed Analysis:

https://www.tenable.com/blog/cve-2020-1938-ghostcat-apache-tomcat-ajp-file-readinclusion-vulnerability-cnvd-2020-10487

Are there any steps that customers can take immediately to workaround this issue until a patch is released?