IBM Support

Release of Guardium Data Protection patch 12.0p145

Release Notes


Abstract

This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p145, resolved or known issues, security fixes, and notices associated with the patch.

Content

Patch information
  • Patch file name: SqlGuard-12.0p145_Bundle_Jul_07_2026.tgz.enc.sig
  • MD5 checksum: 838d72933c1d783aaadbe84a453ef10c
 

Finding the patch

  1. Select the following options to download this patch on the IBM Fix Central website and click Continue.
    • Product selector: IBM Security Guardium
    • Installed Version: 12.1
    • Platform: All
  2. On the "Identify fixes" page, select Browse for fixes and click Continue.
  3. On the "Select fixes" page, select Appliance Bundle. Then, enter the patch information in the Filter fix details field to locate the patch.
 
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
 
 
Prerequisites
  • Guardium Data Protection 12.1 (GPU 12.0p100, see release notes)
  • The latest Guardium Data Protection health check patch 12.0p9997 (see release notes)
 
 

Installation

Notes:
  • This patch includes fixes for version 12.1.
  • This patch is cumulative and includes all the fixes from previously released patches.
  • This patch restarts the Guardium system.
  • Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
  • When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
 
Overview:
  1. Download the patch and extract the compressed package outside the Guardium system.
  2. Review the latest version of the patch release note just before you install the patch.
  3. Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
  4. Apply the latest health check patch.
  5. Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
  6. Apply the special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, and latest Rapid Response DPS patch.
 
For information about installing Guardium Data protection patches, see How to install patches in the Guardium documentation.
 
 
Attention

Special Guardium Database Protection Service update (for Vulnerability Assessment only) 
A special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, which is available for download from Fix Central, must be applied after you upgrade to Guardium 12.p145 from previous versions. See release notes for detailed file information. 
 
If the Special DPS update is not applied, customers might see some false positive results from their Vulnerability Assessment scans for Microsoft SQL Server CVE tests. 
 
Be sure to also check Fix Central for the latest Rapid Response DPS release and apply it after uploading the Special DPS file.
 

Guardium patch signing certificate expired on 29 March 2025
The previous patch signing certificate for Guardium appliance patches expired on 29 March 2025. Guardium appliance patches are signed by an internal certificate to validate that the patch is created by Guardium. Unsigned patch files cannot be installed. This patch is signed by the new patch signing certificate. Therefore, to install this patch, the patch signing certificate on your Guardium appliance must first be updated. For more information, see IBM Guardium - Patch signing certificate set to expire in March 2025 or contact IBM Support.

IBM Db2 for z/OS JDBC driver update       
In 12.0p115 (see release note), the IBM Db2 for z/OS JDBC driver in Guardium Vulnerability Assessment is updated to support IBM Db2 13 for z/OS, which enables TLS 1.3 and other advantages. You might need to update your IBM Db2 JDBC license. If so, test your connection in a staging environment and contact the IBM Db2 Support team if licensing issues arise. For assistance, open a case at ibm.com/mysupport.

 

Resolved issues
PatchIssue keySummaryKnown issue (APAR)
12.0p140 This patch includes resolved issues from 12.0p140 (see release note) 
12.0p145GRD-106013Delimiter fields cannot be moved up or down in the reportDT449749
 GRD-111204Data Import fails with error "Failed decrypting file (suffix=decrypt_failed)"DT460220
 GRD-111904Add utilities to manage certificates monitored for distributionDT468071
 GRD-115800Error while running import scanner_agent scp <agent>. Cannot open rpmkeys file.DT467875
 GRD-115955Mismatch between the DNS-resolved hostname in lowercase and the uppercase hostname set in the ADMINCONSOLE_PARAMETER, which affected the change tracker functionalityDT459423
 GRD-117233Cannot access Guardium with IP address after SAML migrationDT462205
 GRD-117234Deployment Health Table incorrectly reports SYSLOG and SMTP alerters as inactive after service recoveryDT469441
 GRD-117559Incorrect OS field value for Vulnerability Assessment Test ID 798 Cassandra Default PasswordDT463688
 GRD-117778Buffer Usage monitoring and Enterprise Buffer Usage reports not available for Kafka nodes 
 GRD-118663Deployment heath shows collector aggregation status as "status unavailable"DT469394
 GRD-118761REST API remote source hostname becomes case-sensitive after upgraded from version 11.4DT467870
 GRD-119981Updates duo‑universal‑sdk to version 1.3.1 to resolve authentication failures during Guardium user interface login. Only customers who use Cisco Duo MFA for authentication are affected. For more information, see Guardium GUI Login Failure with Duo MFA. 
 GRD-121194Login report shows success for failed login attempts on disabled admin userDT467803
 GRD-121826SNMP alerter service stops unexpectedly preventing trap deliveryDT467797
 GRD-121950Backport MongoDB Vulnerability Assessment Test ID 897DT474738
 GRD-122334AWS Kinesis stream discovery fails with IAM instance profile authentication 
 GRD-122489Support custom signed certificates for Kafka nodesDT467859
 GRD-122755Real-time Trust Evaluator displays decommissioned collectors instead of active onesDT473919
 GRD-123329CAS certificate not regenerated after delete and restore from defaultDT468895
 GRD-123672False positive results from Vulnerability Assessment scans for Microsoft SQL Server CVE testsDT469687
 GRD-123786Multiple managed units show intermittent "unit not responding" in Deployment Health tableDT473163
 GRD-124115Default guardium user account cannot be deletedDT469430
 GRD-124295Aggregation/Archive Report displays incomplete hostname for central manager backup activitiesDT469390
 GRD-124613grdapi copy_key_file command was not available for Kafka-Node appliancesDT469438
 GRD-127456Azure Storage connection string fails to parseDT473842
 GRD-127773Permissions-related bug prevented the change_tracker_get_params command from executing successfully in managed unitsDT474303
 GRD-127898Appliance disk space filling up due to syslog messages 
 GRD-128574Resolve GIM server support for new 12.x versioning convention for single-stream agent release packages. Only customers who use GIM to install and manage agents are affected. For more information, see Single-stream agent releases. 

 
Security fixes
PatchIssue keySummaryCVE
12.0p140 This patch includes security fixes from 12.0p140 (see release note) 
12.0p145GRD-124981PSIRT - PVR0760981, PVR0763120 : libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner)CVE-2026-41603, CVE-2026-43869
 GRD-117726PSIRT : PVR0697335 log4j-core-2.17.1.jar (Publicly disclosed vulnerability found by Scanner) -- cruise-controlCVE-2025-68161
 GRD-119200PSIRT : PVR0710436 IBM Java (Publicly disclosed vulnerability found by Scanner)CVE-2026-1188
 GRD-102088PSIRT: PVR0668193 - commons-beanutils-1.9.2.jar (Publicly disclosed vulnerability found by Mend) - spectrum protect (tivoli)CVE-2025-48734
 GRD-116334PSIRT: PVR0694349 - lz4-1.3.0.jar (Publicly disclosed vulnerability found by Scanner) - Datastreams
CVE-2025-66566
 GRD-124470PSIRT: PVR0754821 - IBM SDK, Java Technology Edition Quarterly CPU - Apr 2026 - Includes Oracle April 2026 CPUCVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007
 GRD-124978PSIRT: PVR0761523 - postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42198
 
 
Known limitations and workarounds
Issue keySummary
GRD-130096

If after running command to disable CBC ciphers (store ciphers java secure disable cbc), a command to disable DHE ciphers is run (store ciphers java secure disable dhe), the CBC ciphers are enabled again.

Workaround: Run command store ciphers java secure disable cbc again to disable CBC ciphers.

GRD-130103

Running the store alerter snmp traphost command does not set the Alerter SNMP trap server to receive alerts as expected. 

Workaround: Use the GUI to set the Alerter SNMP trap server. Go to go to Setup > Tools and Views > Alerter and follow the  Configure the alerter to use SNMP procedure in product documentation. 

 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.1.0"}]

Document Information

Modified date:
09 July 2026

UID

ibm17275624