﻿Cumulative Update for WebOffice 10.9 R5
=======================================
Build time: 20260912-0753 (= Build #238)

* This is an add-on patch for WebOffice 10.9 R5. That means, WebOffice 10.9 R5 is a minimum requirement and must be installed! This patch contains all fixes since WebOffice 10.9 R5! 
* Please inform your users to delete the browser cache according our [guideline](https://resources.weboffice.vertigis.com/Documentation/WebOffice/EN/index.html?trouble_delete_browser_cache.htm), before opening WebOffice the first time after applying an upgrade.


Requirements:{#requirement}
---------------------------
- Installation of VertiGIS WebOffice 10.9 R5 (min. build time: 20251210-1537)  

- Installation of [VertiGIS WebOffice author standalone 10.9 R5 - min. Build 109.5.0.135](https://resources.weboffice.vertigis.com/WebOffice109R5/WebOffice_author_Standalone/WebOffice_author_standalone_109_5_0_135.zip)

- Optional: Installation of [VertiGIS Studio Printing Engine (CIM2) -  Build 5.32.0.11 (ArcGIS 10.8.1 - ArcGIS 10.9.1)](https://support.vertigis.com/hc/en-us/articles/10257643887250)
  - Important: For WebOffice the build “v2” is normally required, which is based on the [Cartographic Information Model (CIM)](https://github.com/esri/cim-spec) v.2 and can be used with ArcGIS Pro 2.x and ArcGIS Enterprise 10.8.x and 10.9.x. Version “v3” is based on CIM v.3 and is only compatible with ArcGIS Pro 3.x and ArcGIS Enterprise 11.x. Background information can be found in the [following HelpCenter article](https://support.vertigis.com/hc/en-us/articles/18772434800914).


Installation:{#installation}
----------------------------
1. Backup your entire WebOffice web-application (e.g. `C:\Tomcat\webapps\<WebOffice web-application>`) to a save place
2. Stop Apache Tomcat (Start/Programs/Administrative Tools/Services)
3. Delete the working directory of Apache Tomcat at e.g. `C:\Tomcat\work\Catalina\localhost\<WebOffice web-application>`
4. Update "ArcGIS Server Object Extension for WebOffice" at least to: **109.5.0.202609111546**
  * In ArcGIS Server Manager under "Services" choose to stop the Map Service "SynOutputService" (or all services, where "WebOffice Server Object Extension" is activated) 
  * In ArcGIS Server Manager under "Site/Extensions" choose to edit "WebOffice Server Object Extension" and select "`<Patch>\ArcGIS for Server Object Extension\syn_soe_ao_gateway.soe`" to upload
    * Don't use uninstall and install the extension, because else you have to set the properties for "WebOffice Server Object Extension" again!    
  * Copy the content of `<Patch>\WebOfficeSystem` to `<Drive>\arcgisserver\directories\WebOfficeSystem`
  * In ArcGIS Server Manager under "Services" choose to start the Map Service "SynOutputService" (or all services, where "WebOffice Server Object Extension" is activated) 
5. Copy WO109R5_patch_YYYYMMDD.exe to the directory of your WebOffice web-application (e.g. `C:\Tomcat\webapps\<WebOffice web-application>`)
6. Run WO109R5_patch_YYYYMMDD.exe and choose to overwrite all existing files
7. Delete the file WO109R5_patch_YYYYMMDD.exe
8. Start Apache Tomcat (Start/Programs/Administrative Tools/Services)


Changelog since WebOffice 10.9 R5:{#changelog}
----------------------------------------------
<!--
### [Unreleased]{#unreleased}
- #### Added
- #### Fixed
- #### Changed
- #### Deprecated
- #### Removed
- #### Security
-->

### [2026-09-10]{#patch20260912}
- #### Added
  - **394752**: General: Support for providing an [SBOM (Software Bill of Materials)](https://en.wikipedia.org/wiki/Software_supply_chain) for VertiGIS WebOffice
  - **394866**: VertiGIS Printing: Support for VertiGIS Studio Printing Engine v5.32.0.11
  - **397896**: SynAdmin: Support for exporting project initialization details as a CSV file
  - **397900**: SynAdmin: Support for WebOffice Logfile Explorer
- #### Fixed
  - **173060**: General: Redlining with a single coordinate point (line) was silently discarded instead of being displayed as a point
  - **173169**: General: Optimization of error messages when the WebOfficeDataShare configuration is invalid
  - **173242**: General: Error initializing an ArcGIS map service when the ArcGIS Server version number cannot be read
  - **223416**: Core: In Firefox, the full-screen icon is not displayed for the ArcGIS WebScene Custom Tool
  - **234099**: General: Excel export fails if a result field linked to an external application does not have a valid link destination
  - **248293**: General: Error retrieving a saved query on ArcGIS Server map services that do not support the query operation
  - **250060**: General: MS Access databases generate a very large number of log entries in the Apache Tomcat log file
  - **302356**: Core: Google Maps Custom Tool: Configured map type is not taken into account
  - **305322**: WebOffice SOE: The SOE Gateway status page did not work with current Java versions
  - **311286**: General: Certain WMS/WMTS services with Basic Authentication are not displayed
  - **333106**: General: Error when UserManagement returns an empty element in the role permissions list
  - **336738**: Core: Feature status (on/off) is not carried over to the StateID for AnnotationSublayers
  - **361857**: VertiGIS Printing: Further optimization for print series using selected objects
  - **375768**: General: Project fails to start if a GPServer URL is incorrectly configured for the “ArcGIS Server Extract Service” instead of a MapServer URL
  - **376033**: General: ePaper reports cannot be generated in all scenarios using an external application integration
  - **378620**: General: Unloaded projects are not available on the landing page
  - **380037**: Core: When using the “Overlay Map” tool, a modified overlay only becomes visible after panning or zooming
  - **381048**: Core: Certain combinations of ribbon configurations cause an error message in the browser console
  - **386987**: General: A regression caused by **336738** prevents SaveStates from older WebOffice versions from loading correctly
  - **387091**: General: WebOffice projects do not start if the URL for the FTS-Index application is not configured correctly
  - **390053**: VertiGIS Printing: Selections on a basemap were not included in the print output
  - **390895**: Core: Error when uploading a KML file if no temporary group layer is found
  - **392442**: Core: The “Export Map” tool does not include the selection
  - **394750**: SynAdmin: SQL Server 2022 and 2025 are not displayed with descriptive edition names
  - **394914**: General: The MGRS Custom Tools do not reference the correct ArcGIS Maps SDK for JavaScript version of the WebOffice application
  - **395075**: General: Sporadic connection errors when connecting to full-text search
  - **395114**: Map Widget: Error with certain tool configurations
  - **395126**: General: Relative or protocol-less service URLs are sometimes no longer recognized correctly
  - **396717**: General: Incorrect session handling can lead to access errors in certain proxy scenarios
  - **396763**: General: Error messages for token errors now include additional context information
  - **396764**: General: Log messages for missing project parameters have been made more concise and informative
  - **396809**: General: The encoding of composite URLs with prefixes/suffixes when calling external applications is incorrect in certain cases
  - **396885** : General: Unclear error message when an editing layer lacks both an ObjectID field and a PrimaryField configuration
  - **396957**: General: The tool for dynamically adding an ArcGIS Server service ignores the preconfigured map service properties, such as image format and timeout
  - **396985**: General: Excessive log file entries during OGC service token validation have been reduced
  - **396986**: General: [Esri World Imagery Wayback WMTS services](https://livingatlas.arcgis.com/wayback/) cause unnecessary warnings in the log file
  - **396993**: General: When unexpected HTML responses are received from services (e.g., due to proxy or maintenance pages), a readable excerpt should be displayed in the error message instead of raw HTML
  - **396995**: WebOffice SOE: When retrieving legend information, an empty icon image caused an error instead of being correctly displayed as empty
  - **396996**: General: Error when starting a project without an active session in certain scenarios
  - **397118**: General: Certificate errors in the WebOffice log file should be more descriptive and include troubleshooting tips
  - **397125**: WebOffice SOE: Resolved ambiguous assignment of configuration values in rare cases
  - **397155**: VertiGIS Printing: Error message after the timeout period during printing has been expanded to include more details
  - **397649**: WebOffice SOE: Optimization of the SOE Gateway status query on Windows servers
  - **397768**: General: Errors when checking whether edit layers are actually available for editing should be made more descriptive in the WebOffice log file and include troubleshooting tips
  - **397796**: General: Error when checking the password change tool if UserManagement has not yet been initialized
  - **397812**: General: Repeated, identical warnings are logged with every request
  - **397814**: General: An empty server response to a WMS map query resulted in an error instead of an empty map view
  - **397817**: General: The error message for an invalid external application URL should no longer display the raw technical class name
  - **397850**: General: Duplicate, context-less log entries should be avoided
  - **397894**: General: Recurring log messages regarding missing configured fields for full-text search should not be logged every 90 seconds
  - **397895**: VertiGIS Printing: Recurring log message regarding a missing print template should be logged only once, rather than once per session
  - **397983**: WebOffice SOE: Map services with certain mosaic datasets caused an error
  - **397984**: WebOffice SOE: More informative error message for failed SOE transactions
  - **398011**: WebOffice SOE: Log message for an SOE gateway error should indicate the area actually affected
  - **398084**: General: Errors when accessing the ArcGIS Server Admin Interface should be logged in the WebOffice log file in a more descriptive manner and include troubleshooting tips
  - **398093**: General: Repeated, identical permission errors should be logged only once per session instead of on every call
  - **398191**: General: Indications of broken data sources in an MXD underlying an ArcGIS Server map service, detected by the WebOffice SOE, should be passed on to the WebOffice log file
  - **398347**: WebOffice SOE: Map services from current ArcGIS Server versions generate many log entries at the DEBUG level
  - **398413**: WebOffice SOE: Fixed an incorrectly formatted diagnostic message caused by invalid data from ArcGIS Server
  - **398582**: Core: Various optimizations for ArcGIS WebScene: basemap filters, Building Explorer, coordinate conversion
  - **398600**: General: If there are too many failed login attempts, an appropriate message should be displayed to the end user
  - **398782**: Core: Export of client-side log files fails when certain special characters are present
  - **398785**: General: OGC WFS services with a large number of feature types generate an unnecessarily long log entry when a feature type is missing
  - **398799**: Core: Error in "Customer Information" if the browser window size is changed during loading
  - **398837**: SynAdmin: VectorTile services cause users to be logged out of SynAdmin due to an expired session when switching to the "Map Services" tab
  - **398876**: General: An incorrect GeoOffice Online (AGDA) configuration prevents the project from starting altogether
  - **398881**: General: Fixed a potential memory leak and warnings in the Apache Tomcat log file  
- #### Changed
  - **397602**: General: Update the Oracle JDBC driver to v23.8.0.25.04
  - **398878**: General: Technical modernization of the GeoOffice Online (AGDA) integration  
- #### Security
  - **376785**: General: Replace log4j v1.2.17 with reload4j v1.2.26
  - **394854**: General: Update the Excel export library (= Apache POI to v5.5.1)
  - **394855**: General: Switch the PDF library from iText v2.1.9 to OpenPDF v2.4.0
  - **394897**: General: Update Spring Framework to v6.2.19
  - **394904**: General: Updated the aircompressor library to v2.0.3
  - **394905**: General: Updated the SQLite JDBC driver to v3.53.2.1
  - **394906**: General: Updated the PostgreSQL JDBC driver to v42.7.13
  - **394907**: General: Updated the Microsoft JDBC driver for SQL Server to v12.2.1
  - **394908**: General: Updated the OWASP Java HTML Sanitizer to v20260101.1
  - **394909**: General: Updated Apache Commons Configuration2 to v2.12.0
  - **394911**: General: Password parameters could be displayed unprotected in certain error messages
  - **394957**: Core: XXE vulnerability when processing XML data during the upload of a GPX file
  - **395049**: General: Updated the SwaggerUI library to v5.32.14
  - **396879**: General: Updated Jackson Databind to v2.18.9
  - **396880**: General: Updated Apache Commons Configuration2 to v2.15.1
  - **396881**: General: Updated the Log4j API to v2.2.6.1
  - **396882**: General: Updated the full-text search components (Solr/Jetty)
  - **398173**: Core: Fixed a stored XSS vulnerability in saved queries  


### [2026-07-01]{#patch20260701}
- #### Fixed
  - **371012**: SynAdmin: Error logging in after entering a password containing certain special characters
  - **386776**: General: A version conflict with the [GeoTools library](https://www.geotools.org/) causes the GeoTIFF export to fail
  - **387091**: General: Expanded log information regarding the ProxySelector


### [2026-06-23]{#patch20260623}
- #### Fixed
  - **386550**: Map Widget: Error when creating objects in crosshair mode because the “Create or Link” tool's link logic is incorrectly executed in the background


### [2026-06-11]{#patch20260611}
- #### Added
  - **343734**: Flex: Support for creating ePaper reports via ScriptAPI
- #### Fixed
  - **381088**: General: Regression from **370605** causes an error when printing if the "Aggregate the rights (restrictions) of multiple role membership?" parameter is set to "false" in UserManagement  
  - **375511**: SynAdmin: Regression caused by the switch to Java 21 results in valid MAC addresses also being listed under "Not valid for licensing"
  - **376033**: Core: ePaper report cannot be generated from an external application integration using generate_epaper.jsp 
  - **380608**: General: In "Visible Layers" mode, the MapTip for WMS layers is displayed even though the WMS layer is not active in the TOC
  - **381976**: VertiGIS Printing: After a filtered search, all objects appear in the printout and no filtering takes place


### [2026-05-20]{#patch20260520}
- #### Fixed
  - **379547**: General: A regression caused by **370605** prevents tools such as printing from working in some scenarios
  - **380037**: Core: The "Overlay Map" tool does not work with ArcGIS Maps SDK for JavaScript 4.34
- #### Changed
  - **378055**: General: Updated to [Swagger Core 3 version 2.2.49](https://github.com/swagger-api/swagger-core)


### [2026-05-10]{#patch20260510}
- #### Added
  - **376820**: VertiGIS Printing: Support for VertiGIS Studio Printing Engine v5.30.2.2 
- #### Fixed
  - **375971**: General: WMS services with swapped axis order are not displayed because WebOffice does not pass the bounding box parameter correctly
  - **378599**: Core: WebOffice projects do not start when WebOffice layer filters with lookups are used and no default value is specified
- #### Changed
  - **323585**: General: Update of the [EPSG codes](https://epsg.org/) and axis orientations stored in WebOffice to version [12.055](https://epsg.org/whatsnew.html)
- #### Security
  - **370605**: Core: It must be checked whether the EDIT, UPLOAD, PRINT, EXTRACT, and EPAPER tools are enabled for the user in the session and whether the user is authorized for the corresponding tools


### [2026-04-08]{#patch20260408}
- #### Added
  - **341204**: Flex: Support for configuring animation behavior and animation speed
- #### Fixed
  - **356029**: Core: Map services do not reload in certain scenarios when transparency is applied to map services
  - **361857**: VertiGIS Printing: Print series over selected objects does not work
  - **362159**: Core: Panorama images should not require storage in subdirectories derived from the filename
  - **364181**: VertiGIS Printing: On a rotated map, the label is not correctly aligned
  - **368688**: Core: Error when uploading a GPX file
  - **368790**: Flex: An error during identify causes the WebOffice Flex client to freeze 
  - **368851**: General: Certain WFS services cause an error message in the WebOffice log file
  - **374322**: Core: Error with the "Export Map" and "GeoTIFF export" tool
- #### Security
  - **370602**: General: After entering an incorrect password during a login process, the WebOffice application server must not send the password to the WebOffice client


### [2026-02-27]{#patch20260227}
- #### Added
  - **341204**: Core: Support for configuring animation behavior and animation speed
  - **344723**: Core: Support for "generateState" in the ScriptAPI for creating a SaveState
  - **358317**: Core: Support for Maptip on layers of a WMS service that support the Identify operation
  - **365665**: VertiGIS Printing: Support for VertiGIS Studio Printing Engine v5.29.1.2
- #### Fixed
  - **344358**: Flex: Extract via popup (Identify/Search) on a GIS object does not work
  - **344667**: Core: Regression from **325600** causes problems with the map overlay tool
  - **358540**: General: WebOffice layer filter on layers configured with identical code value domains does not work  
  - **362499**: General: At WebOffice SOE print with dynamic legend, legend symbols are shifted if the underlying font contains symbols in different sizes
- #### Security
  - **233833**: General: Update to [jQuery 3.7.1](https://blog.jquery.com/2023/08/28/jquery-3-7-1-released-reliable-table-row-dimensions/) - Important: All individually created JSP files that reference the included jQuery library may need to be adjusted during the update
  - **360547**: General: Update [Apache Commons Text](https://commons.apache.org/proper/commons-text/) to version [1.15.0](https://commons.apache.org/proper/commons-text/changes.html#a1.15.0)


IMPORTANT:
----------
* All fixes have been tested on base of bug reports of our customers.
* Due the high complexity of this product we can't avoid regressions for sure.

##### This changelog was created with [Pandoc](https://pandoc.org/) using [Markdown](https://www.markdownguide.org) according [Keep a Changelog](https://keepachangelog.com/) and [Make a README](https://www.makeareadme.com/).
