Zimbra Releases/9.0.0/P44
Zimbra Collaboration Kepler 9.0.0 Patch 44 GA Release
Release Date: January 27, 2025
Check out the Security Fixes for this version of Zimbra Collaboration.
Please refer to the Patch Installation page for Patch Installation instructions.
As always, you are encouraged to tell us what you think in the Forums or open a support ticket to report issues
Things to know before you upgrade
Changes to SOAP API
There are changes in ChangePassword SOAP API. Please refer to API reference documentation. If you have custom auth implementation with ChangePassword, please incorporate changes to support new API changes.
Security Fixes
Summary | CVE-ID | CVSS Score |
---|---|---|
This patch fixes a critical security vulnerability related to stored cross-site scripting in the Zimbra Classic Web Client. The fix strengthens input sanitization and enhances security. All customers are strongly advised to upgrade to this latest patch version immediately. |
Packages
Jira ticket:
The package lineup for this release is:
zimbra-patch -> 9.0.0.1737696708.p44-2 zimbra-mbox-webclient-war -> 9.0.0.1737655418-1
Patch Installation
Please refer to below link to install Kepler 9.0.0 Patch 44:
Quick note: Open Source repo
The steps to download, build, and see our code via Github can be found here: https://github.com/Zimbra/zm-build