IBM Support

Release of Guardium Data Protection sniffer patch 11.0p4078

Release Notes


Abstract

This technical note provides guidance for installing IBM Security Guardium Data Protection sniffer patch 11.0p4078, including any new features or enhancements, resolved or known issues, or notices associated with the patch.

Content

Patch information
  • Patch file name: SqlGuard-11.0p4078_Snif_Aug_16_2024.tgz.enc.sig
  • MD5 checksum: 5b88a2d304989217c7aebe11d9b66dd3
Finding the patch 
Make the following selections to locate this patch for download on the IBM Fix Central website:
 
  • Product selector: IBM Security Guardium
  • Installed version: 11.0
  • Platform: All
  • Click "Continue," select "Browse for fixes," and click "Continue" again.
  • Enter the patch information in the "Filter fix details" field to locate the patch
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
Prerequisite
Guardium version 11.0
Installation
Notes:
  • This universal sniffer patch can be installed on all releases of Guardium 11.x
  • This patch restarts the sniffer process.
Overview:
  1. Download the patch and extract the compressed package outside the Guardium system.
  2. Be sure to check the latest version of these patch release notes online just before you install this patch.
  3. Pick a "quiet" or low-traffic time  to install the patch on the Guardium system.
  4. Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.  This sniffer patch must be installed across all the appliances such as the central manager, aggregators, and collectors.
For information about installing Guardium Data protection patches, see How to install patches in the Guardium documentation.
New currency items
This patch provides the following new currency items:
Issue key Summary
GRD-82427 Support Oracle Database 23ai Free
GRD-77487 Support Oracle Database 23c on Oracle Cloud Infrastructure
GRD-78353 Support CockroachDB 23.2.0
GRD-80052 Support Redis 7.4
GRD-81097 Support MySQL 8.3.0
Enhancements
This patch provides the following enhancements:
Issue key Summary
GRD-73431 Implement ANTLR3 Impala parser
GRD-74631
Template Multiple failed login quarantine.
GRD-76108
Sniffer side of Internal Load Balancer
GRD-78158
Exclude explain command from calling QRW
GRD-82398 Snif side changes to retrieve cert from keystore
GRD-84748 Update feed server to use SSL keystore
INS-35097 Make object and verb a sub-document in instance rather than a comma separated string
Resolved issues
This patch resolves the following issues:
Patch Issue key Summary APAR
11.0p4077 -- Patch 11.0p4077 on Fix Central --
11.0p4078 GRD-77365 Some expected Microsoft SQL Server queries not logged on collector DT382325
GRD-82553 Successful Microsoft SQL Server ALTER PROCEDURE statement caused PARSER_ERROR DT386758
GRD-83434 Sniffer crashing due to record larger than 64,000 characters with AWS feed traffic DT391328
GRD-84172 Query rewrite issue on count(*) with IBM Db2 SQL query
DT391634
Known limitations
This patch contains the following known limitations:
Issue key Summary
GRD-85591
Under certain circumstances, the collector can corrupt failover messages that are sent to the S-TAP over protocol 8.
Workaround: Use protocol 7 until the collector problem is fixed in future sniffer patches.

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
22 August 2024

UID

ibm17162384