Release Notes
Abstract
This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p145, resolved or known issues, security fixes, and notices associated with the patch.
Content
- Patch file name: SqlGuard-12.0p145_Bundle_Jul_07_2026.tgz.enc.sig
- MD5 checksum: 838d72933c1d783aaadbe84a453ef10c
Finding the patch
- Select the following options to download this patch on the IBM Fix Central website and click Continue.
- Product selector: IBM Security Guardium
- Installed Version: 12.1
- Platform: All
- On the "Identify fixes" page, select Browse for fixes and click Continue.
- On the "Select fixes" page, select Appliance Bundle. Then, enter the patch information in the Filter fix details field to locate the patch.
- Guardium Data Protection 12.1 (GPU 12.0p100, see release notes)
- The latest Guardium Data Protection health check patch 12.0p9997 (see release notes)
Installation
- This patch includes fixes for version 12.1.
- This patch is cumulative and includes all the fixes from previously released patches.
- This patch restarts the Guardium system.
- Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
- When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
- Download the patch and extract the compressed package outside the Guardium system.
- Review the latest version of the patch release note just before you install the patch.
- Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
- Apply the latest health check patch.
- Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
- Apply the special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, and latest Rapid Response DPS patch.
Special Guardium Database Protection Service update (for Vulnerability Assessment only)
Guardium patch signing certificate expired on 29 March 2025
The previous patch signing certificate for Guardium appliance patches expired on 29 March 2025. Guardium appliance patches are signed by an internal certificate to validate that the patch is created by Guardium. Unsigned patch files cannot be installed. This patch is signed by the new patch signing certificate. Therefore, to install this patch, the patch signing certificate on your Guardium appliance must first be updated. For more information, see IBM Guardium - Patch signing certificate set to expire in March 2025 or contact IBM Support.
IBM Db2 for z/OS JDBC driver update
In 12.0p115 (see release note), the IBM Db2 for z/OS JDBC driver in Guardium Vulnerability Assessment is updated to support IBM Db2 13 for z/OS, which enables TLS 1.3 and other advantages. You might need to update your IBM Db2 JDBC license. If so, test your connection in a staging environment and contact the IBM Db2 Support team if licensing issues arise. For assistance, open a case at ibm.com/mysupport.
| Patch | Issue key | Summary | Known issue (APAR) |
|---|---|---|---|
| 12.0p140 | This patch includes resolved issues from 12.0p140 (see release note) | ||
| 12.0p145 | GRD-106013 | Delimiter fields cannot be moved up or down in the report | DT449749 |
| GRD-111204 | Data Import fails with error "Failed decrypting file (suffix=decrypt_failed)" | DT460220 | |
| GRD-111904 | Add utilities to manage certificates monitored for distribution | DT468071 | |
| GRD-115800 | Error while running import scanner_agent scp <agent>. Cannot open rpmkeys file. | DT467875 | |
| GRD-115955 | Mismatch between the DNS-resolved hostname in lowercase and the uppercase hostname set in the ADMINCONSOLE_PARAMETER, which affected the change tracker functionality | DT459423 | |
| GRD-117233 | Cannot access Guardium with IP address after SAML migration | DT462205 | |
| GRD-117234 | Deployment Health Table incorrectly reports SYSLOG and SMTP alerters as inactive after service recovery | DT469441 | |
| GRD-117559 | Incorrect OS field value for Vulnerability Assessment Test ID 798 Cassandra Default Password | DT463688 | |
| GRD-117778 | Buffer Usage monitoring and Enterprise Buffer Usage reports not available for Kafka nodes | ||
| GRD-118663 | Deployment heath shows collector aggregation status as "status unavailable" | DT469394 | |
| GRD-118761 | REST API remote source hostname becomes case-sensitive after upgraded from version 11.4 | DT467870 | |
| GRD-119981 | Updates duo‑universal‑sdk to version 1.3.1 to resolve authentication failures during Guardium user interface login. Only customers who use Cisco Duo MFA for authentication are affected. For more information, see Guardium GUI Login Failure with Duo MFA. | ||
| GRD-121194 | Login report shows success for failed login attempts on disabled admin user | DT467803 | |
| GRD-121826 | SNMP alerter service stops unexpectedly preventing trap delivery | DT467797 | |
| GRD-121950 | Backport MongoDB Vulnerability Assessment Test ID 897 | DT474738 | |
| GRD-122334 | AWS Kinesis stream discovery fails with IAM instance profile authentication | ||
| GRD-122489 | Support custom signed certificates for Kafka nodes | DT467859 | |
| GRD-122755 | Real-time Trust Evaluator displays decommissioned collectors instead of active ones | DT473919 | |
| GRD-123329 | CAS certificate not regenerated after delete and restore from default | DT468895 | |
| GRD-123672 | False positive results from Vulnerability Assessment scans for Microsoft SQL Server CVE tests | DT469687 | |
| GRD-123786 | Multiple managed units show intermittent "unit not responding" in Deployment Health table | DT473163 | |
| GRD-124115 | Default guardium user account cannot be deleted | DT469430 | |
| GRD-124295 | Aggregation/Archive Report displays incomplete hostname for central manager backup activities | DT469390 | |
| GRD-124613 | grdapi copy_key_file command was not available for Kafka-Node appliances | DT469438 | |
| GRD-127456 | Azure Storage connection string fails to parse | DT473842 | |
| GRD-127773 | Permissions-related bug prevented the change_tracker_get_params command from executing successfully in managed units | DT474303 | |
| GRD-127898 | Appliance disk space filling up due to syslog messages | ||
| GRD-128574 | Resolve GIM server support for new 12.x versioning convention for single-stream agent release packages. Only customers who use GIM to install and manage agents are affected. For more information, see Single-stream agent releases. |
| Patch | Issue key | Summary | CVE |
|---|---|---|---|
| 12.0p140 | This patch includes security fixes from 12.0p140 (see release note) | ||
| 12.0p145 | GRD-124981 | PSIRT - PVR0760981, PVR0763120 : libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2026-41603, CVE-2026-43869 |
| GRD-117726 | PSIRT : PVR0697335 log4j-core-2.17.1.jar (Publicly disclosed vulnerability found by Scanner) -- cruise-control | CVE-2025-68161 | |
| GRD-119200 | PSIRT : PVR0710436 IBM Java (Publicly disclosed vulnerability found by Scanner) | CVE-2026-1188 | |
| GRD-102088 | PSIRT: PVR0668193 - commons-beanutils-1.9.2.jar (Publicly disclosed vulnerability found by Mend) - spectrum protect (tivoli) | CVE-2025-48734 | |
| GRD-116334 | PSIRT: PVR0694349 - lz4-1.3.0.jar (Publicly disclosed vulnerability found by Scanner) - Datastreams | CVE-2025-66566 | |
| GRD-124470 | PSIRT: PVR0754821 - IBM SDK, Java Technology Edition Quarterly CPU - Apr 2026 - Includes Oracle April 2026 CPU | CVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007 | |
| GRD-124978 | PSIRT: PVR0761523 - postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42198 |
| Issue key | Summary |
|---|---|
| GRD-130096 | If after running command to disable CBC ciphers (store ciphers java secure disable cbc), a command to disable DHE ciphers is run (store ciphers java secure disable dhe), the CBC ciphers are enabled again. Workaround: Run command store ciphers java secure disable cbc again to disable CBC ciphers. |
| GRD-130103 | Running the store alerter snmp traphost command does not set the Alerter SNMP trap server to receive alerts as expected. Workaround: Use the GUI to set the Alerter SNMP trap server. Go to go to Setup > Tools and Views > Alerter and follow the Configure the alerter to use SNMP procedure in product documentation. |
Was this topic helpful?
Document Information
Modified date:
09 July 2026
UID
ibm17275624