News
Abstract
IBM Guardium is impacted by an issue with the duo‑universal‑sdk used for Duo MFA authentication. The current SDK version causes GUI login failures when Duo MFA is enabled, preventing users from accessing the Guardium UI. Customers who do not use Duo MFA are not affected. This issue does not affect the Guardium 12.2.2 environment.
Content
Symptoms
- Users are unable to log in to the Guardium GUI
- Duo MFA authentication fails during GUI login
Workaround
grdapi configure_mfa mfaType="DUO" enable=false loginPath=GU
Remediation
- Disable Duo MFA for GUI login using the command in the previous Workaround section.
- Log in to the Guardium UI.
- Install the required ad hoc patch that updates duo-universal-sdk to version 1.3.1.
- Re-enable Duo MFA for GUI login. Execute the following command through CLI interface:
grdapi configure_mfa mfaType="DUO" enable=true loginPath=GUI
Note: A GUI restart is not required when disabling or enabling Duo MFA.
Fix availability
IBM is actively delivering fixes for the affected Guardium versions. The update includes duo‑universal‑sdk version 1.3.1. Customers are advised to apply the available workaround if impacted and plan to install the applicable fix once it becomes available for their Guardium version.
| Guardium version | Fix delivery method | Estimated availability |
|---|---|---|
| 11.0p582 for version 11.5 environments | Fix Central | Available. See release notes for 11.0p582. |
| 12.0p56 for version 12.0 environments | Fix Central | Available. See release notes for 12.0p56. |
| 12.0p141 for version 12.1 environments | Fix Central | Available. See release notes for 12.0p141. |
| 12.0p208 for version 12.2 environments | Fix Central | Available. See release notes for 12.0p208. |
| 12.0p1031 | Fix Central | Available. See release notes for 12.0p1031. |
Was this topic helpful?
Document Information
Modified date:
24 April 2026
UID
ibm17269364