Release Notes
Abstract
This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p55, including any new features or enhancements, resolved or known issues, or notices associated with the patch.
Content
Patch information
- Patch file name: SqlGuard-12.0p55_Bundle_Mar_24_2026.tgz.enc.sig
- MD5 checksum: 1c13fff74310fac40601e141944477e7
Finding the patch
- Select the following options to download this patch on the IBM Fix Central website and click Continue.
- Product selector: IBM Security Guardium
- Installed Version: 12.0
- Platform: All
- On the "Identify fixes" page, select Browse for fixes and click Continue.
- On the "Select fixes" page, select Appliance Bundle. Then, enter the patch information in the Filter fix details field to locate the patch.
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
Prerequisites
The latest Guardium Data Protection health check patch 12.0p9997 (see release note)
Installation
Notes:
- This patch is an appliance bundle that includes all fixes for version 12.0.
- This patch is cumulative and includes all the fixes from previously released patches.
- This patch restarts the Guardium system.
- Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
- When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
Overview:
- Download the patch and extract the compressed package outside the Guardium system.
- Review the latest version of the patch release notes just before you install the patch.
- Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
- Apply the latest health check patch.
- Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
- Apply the latest quarterly DPS patch and rapid response DPS patch even if these patches were applied before the upgrade.
For information about installing Guardium Data protection patches, see Installing patches in the Guardium documentation.
Attention
Guardium appliance bundle upgrade time extended due to MySQL tables conversion
Following MySQL support requirements, most tables are converted from MyISAM to InnoDB starting with Guardium appliance bundle versions 11.0p550 and later, and versions 12.0p25 and later. Due to the large size of some tables, which are mostly static tables, the conversion might consume more time than usual during an appliance bundle upgrade. Note: Do not cancel the patch installation process. If you have any concerns, contact IBM Support.
For more information, see Guardium appliance bundle upgrade time extended due to MySQL tables conversion.
Guardium patch signing certificate expired on 29 March 2025
Guardium appliance patches are signed by an internal certificate to validate that the patch is created by Guardium. Unsigned patch files cannot be installed. The previous patch signing certificate for Guardium appliance patches expired on 29 March 2025.
This patch is signed by the new patch signing certificate. Therefore, to install this patch, your Guardium appliance must be prepared by installing an ad hoc or bundle patch with the fix that allows patches signed by old or new certificates to be installed. See IBM Guardium - Patch signing certificate set to expire in March 2025 and follow the steps in the "What to do after March 29th 2025" section if the patch signing certificate was not renewed.
Enhancements
This patch includes the following enhancements.
| Issue key | Summary |
|---|---|
| GRD-101421 | Support for configuring proxy settings with certificates by using the store certificate keystore trusted console CLI command to import the proxy certification authority (CA) certificate into the Guardium keystore across all managed units. The certificate alias can be any arbitrary value. The alias name does not affect functionality. For more information, see Certificate CLI Commands. |
| GRD-115452 | Updated Java Database Connectivity (JDBC) drivers for Oracle, Microsoft SQL Server, Apache Cassandra, and Datastax Cassandra. |
Resolved issues
This patch resolves the following issues.
| Patch | Issue key | Summary | Known issue (APAR) |
|---|---|---|---|
| 12.0p50 | This patch includes fixes from 12.0p50 (see release notes) | ||
| 12.0p55 | GRD-103375 | Values Changed report shows special characters as separators between columns when downloaded to a .csv file | DT448687 |
| GRD-106013 | Delimiter fields cannot be moved up or down in the report | DT449749 | |
| GRD-110653 | Vulnerability Assessment scan results for IBM Db2 for z/OS show message "Unsupported Security PTF patch detected" for Db2 for z/OS Authorized Program Analysis Report (APAR) product temporary fix (PTF) starting with 'UO' prefix | DT454625 | |
| GRD-111204 | Data Import fails with error "Failed decrypting file (suffix=decrypt_failed)" | DT460220 | |
| GRD-111612 | "License key is NULL" message appears when accepting license in GUI after collector is patched to 11.0p550 if appliance language is Japanese | DT455239 | |
| GRD-111789 | Guardium and CyberArk integration for datasource external credentials | DT459546 | |
| GRD-112324 | Guardium appliances stopped sending mails | DT458928 | |
| GRD-112333 | Executing CLI command "show csr wildcard" returns message "Error in converting privatekey to decrypted form for tomcat" in Guardium | DT457503 | |
| GRD-113956 | Failure accessing reports in a shared dashboard | DT457609 | |
| GRD-114046 | Same policy shows several times on GUI on the collector | DT455569 | |
| GRD-114739 | All managed units stay in inactive state on new primary central manager after disaster recovery drill | DT459564 | |
| GRD-115058 | After upgrading Guardium to version 12.2 the Risk Spotter policy disappeared | DT457592 | |
| GRD-115545 | Unable to change SCP port from the default 22 | DT458241 | |
| GRD-116040 | store cli_userauth ldap CLI command failed | DT457706 | |
| GRD-116344 | Central manager reset-managed-cli command fails to reset the CLI password on all managed units | DT458396 | |
| GRD-116567 | Non-admin users able to access details about users using API calls | DT460790 | |
| GRD-117472 | OpenSSH ssh function vulnerability (CVE-2025-61984) | DT463011 |
Security fixes
This patch resolves the following issues.
| Patch | Issue key | Summary | CVE |
|---|---|---|---|
| 12.0p50 | This patch includes fixes from 12.0p50 (see release notes) | ||
| 12.0p55 | GRD-113088 | PSIRT: PVR0682763 - bcpkix-jdk18on-1.78.1.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2025-8916 |
| GRD-113257 | PSIRT: PVR0683789 - vertx-web-4.5.8.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2025-11965, CVE-2025-11966, CVE-2026-1002 | |
| GRD-114000 | PSIRT: PVR0685736 - mssql-jdbc-13.2.0.jre11.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2025-59250 | |
| GRD-114008 | PSIRT: PVR0685130 - IBM SDK, Java Technology Edition Quarterly CPU - Oct 2025 - Includes Oracle October 2025 CPU | CVE-2025-53066, CVE-2025-53057 | |
| GRD-116955 | PSIRT: PVR0702018, PVR0702017 - SE - Pen Testing GDP - 2025 - 3 issues found (2 high, 1 medium) | ||
| GRD-91110 | PSIRT: PVR0559560, PVR0571236 - multiple spring-components (Publicly disclosed vulnerability found by Mend) - webapps | CVE-2024-38820, CVE-2024-38827 |
[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.0.0"}]
Was this topic helpful?
Document Information
Modified date:
22 April 2026
UID
ibm17262733