Zimbra Releases/9.0.0/P44

Zimbra Collaboration Kepler 9.0.0 Patch 44 GA Release

Release Date: January 27, 2025

Check out the Security Fixes for this version of Zimbra Collaboration. Please refer to the Patch Installation page for Patch Installation instructions. As always, you are encouraged to tell us what you think in the Forums or open a support ticket to report issues

Things to know before you upgrade

Changes to SOAP API

There are changes in ChangePassword SOAP API. Please refer to API reference documentation. If you have custom auth implementation with ChangePassword, please incorporate changes to support new API changes.


Security Fixes

Summary CVE-ID CVSS Score
This patch fixes a critical security vulnerability related to stored cross-site scripting in the Zimbra Classic Web Client. The fix strengthens input sanitization and enhances security. All customers are strongly advised to upgrade to this latest patch version immediately.

Packages

Jira ticket:

The package lineup for this release is:

zimbra-patch                                      ->  9.0.0.1737696708.p44-2
zimbra-mbox-webclient-war                         ->  9.0.0.1737655418-1

Patch Installation

Please refer to below link to install Kepler 9.0.0 Patch 44:

Patch Installation


Quick note: Open Source repo

The steps to download, build, and see our code via Github can be found here: https://github.com/Zimbra/zm-build

Jump to: navigation, search