High Performance Starts Here — AMD Dedicated Servers

English

Home

Blog

Zimbra Latest Versions Not Affected by L...

Zimbra Latest Versions Not Affected by Log4j Vulnerability

Zimbra Latest Versions Not Affected by Log4j Vulnerability

NetShop ISP

NetShop ISP · Blog Author

Dec 17, 2021 · Security

This is announcement published by Synacor regarding the zero-day exploit vulnerability for Log4j

After intensive review and testing, Zimbra Development determined that the zero-day exploit vulnerability for Log4j (CVE-2021-44228) does not affect the current supported Zimbra versions 9.0.0 and 8.8.15.

Zimbra Collaboration Server currently uses Log4j version 1.2.16. The cause of the vulnerability is found in the lookup expression feature in Log4j versions 2.0 to 2.17.

Also, the Redhat (CVE-2021-4104) vulnerability does not affect the current Supported Zimbra Collaboration Server versions 9.0.0 and 8.8.15. For this vulnerability to affect the server, it needs JMSAppender and the ability to append configuration files. Zimbra does not use the JMSAppender.

The Zimbra Development team is in the process of upgrading Log4j which is expected to be completed within Q1 2022.

Read more about the Log4j vulnerability and how to protect your organization’s infrastructure.

cyber security
log4j
vulneratibility
zimbra
Press Releases
97

Free VPS Trial

No Credit Card Required.

Start Your VPS Hosting Free Trial

Recent Posts

Hermes AI Agent VPS - Deploy in 1 Click

Introducing Hermes Agent VPS: Your Own AI Agent, Live in One Click

22 July 2026

How To Protect Your Website from DDoS Attacks in 2026

How To Protect Your Website from DDoS Attacks in 2026

14 July 2026

Why Your Stream Keeps Buffering (And How to Fix It)

Why Your Stream Keeps Buffering (And How to Fix It)

08 July 2026

How to Secure Your WordPress Website in 2026

How to Secure Your WordPress Website in 2026

30 June 2026

How To Fix Outdated Theme on cPanel / WHM

Why Your cPanel or WHM Login Page Is Showing an Outdated Theme (And How to Fix It)

22 June 2026