IBM Support

Release of Guardium Data Protection 12.2.3

Release Notes


Abstract

This technical note provides guidance for installing IBM Guardium Data Protection 12.2.3, including any new features or enhancements, resolved or known issues, or associated notices for Guardium patch update (GPU) 12.0p230, Edge patch 12.0p15003, Gen AI patch 12.0p80020, and Data lake (long-term retention) patch 12.0p80103.

Content

Download Guardium 12.2.3 (GPU 12.0p230)
 
IBM Passport Advantage

On Passport Advantage, you can find the Guardium Product Image - ISO file, licenses, product keys, and manuals. You can download only the products that your site is entitled. If you need assistance to find or download a product from the Passport Advantage site, contact the Passport Advantage team at 800-978-2246 (8:00 AM - 8:00 PM ET) or by email at paonline@us.ibm.com.

 
IBM Support Fix Central

On Fix Central, you can find upgrades, Guardium Patch Update (GPU) files, individual patches, and the current versions of database agents, such as Software TAP (S-TAP) and Guardium Installation Manager (GIM). If you need assistance to find a product on Fix Central, contact IBM Support.
 

Install Guardium 12.2.3
Guardium 12.2.3 is available as an ISO product image on Passport Advantage. If the downloaded package is in .zip format, extract it outside of the Guardium appliance before you upload or install it. Review the latest version of these release notes just before you install. Install Guardium across all the appliances, such as the central manager, aggregators, and collectors. For detailed steps, see Installing your Guardium Data Protection system.

 
Upgrade to Guardium 12.2.3 (GPU 12.0p230)

Before you upgrade, confirm that your appliance meets the minimum requirements. Upgrade your firmware to the latest versions provided by your vendor. If you use a Guardium appliance, check Fix Central for the latest firmware. 

You can upgrade to Guardium 12.2.3 (GPU 12.0p230) from Guardium systems that are running on version 12.2.0 (GPU 12.0p200, see release notes). The best approach for upgrading Guardium depends on the version you are upgrading from, the hardware of your system, and any special partitioning requirements you might have. See Identifying the correct upgrade path to review upgrade scenarios and identify the correct upgrade path for your Guardium systems. Review the latest version of these release notes just before you install.

Note: The Guardium system will restart during the upgrade process for all of the patch installations, so schedule the upgrades in batches during low database traffic times to minimize audit gaps. Do not reboot the appliance while the patch installations are in progress. Contact IBM Support if there is an issue with patch installation.

 
Prerequisites
  • Guardium Data Protection 12.0p200 (see release notes)
  • The latest Guardium Data Protection health check patch 12.0p9997
 
Attention
 

Ad hoc patches

When you install GPU 12.0p230 on the central manager, the following ad hoc patches also deploy on the corresponding managed units to allow existing functionality to continue to work properly even if the managed units stay on older patch levels for an extended period of time.

  • 12.0p1044 - Add column RECORDS_AFFECTED_ONLY to DATAMART.AGG_ANALYTIC_INPUT table
  • 12.0p1045 - Update Solr Certificate
  • 12.0p1145 - Add column ASPECT_LEVEL to DATAMART.AGG_ANALYTIC_INPUT table
     

Feature flags

Guardium supports feature flags to help you control when new capabilities are activated in your environment. For Guardium 12.2.3, the following feature patches are available in Fix Central for download/installation: Edge patch 12.0p15003, Gen AI patch 12.0p80020, and Data lake (long-term retention) patch 12.0p80103. For more information, see Applying feature flags


Single stream agent releases

Most of the Linux-UNIX and Windows agents for Guardium Data Protection versions 12.0 and later are now released in a single stream. This simplifies maintenance, reduces version divergence, and ensures consistent feature and fix availability across all supported 12.x environments. For more information, see Single-stream agent releases.

 

Special Guardium Database Protection Service update (for Vulnerability Assessment only)

A special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, which is available for download from Fix Central, must be applied after you upgrade to Guardium 12.2.3 (GPU 12.0p230) from previous versions. See release notes for detailed file information. Be sure to also check Fix Central for the latest Rapid Response DPS release and apply it after uploading the Special DPS file. 

 

New features and enhancements
 

Automated patch downloads
Keep Guardium continuously up to date by letting the service automatically monitor Fix Central for new patches and download them as soon as they become available so you can schedule the installation. Easily enabled through the CLI to reduce manual effort and significantly accelerate upgrade cycles. Note: Requires connectivity to the internet either directly or through an HTTP proxy.

 

Active threat analytics UI 
Streamline onboarding and accelerate risk detection and response with enhanced usability.

  • Modernized setup page to simplify case configurations.

  • Automatic case closure options.

  • Enhanced exclusion criteria with additional parameters and recurrence-based filtering capabilities.

  • Caching of case summaries and policy explanations in the database improves responsiveness and reduces wait times to regenerate content.

  • Server-side pagination for the Active threat analytics cases table improves performance when working with large case volumes, enabling efficient navigation and search across all cases. 

  • What this means feature uses generative AI to explain policy rule violations, helping you understand what triggered violations without interpreting policy builder configurations.

 

Active threat analytics for IBM Db2 z/OS 

Gain more granular analysis of database-level threat detection support for IBM Db2 z/OS environments.

  • 18 updated reports with database-level filtering capabilities.

  • 8 new reports for database-specific threat analysis.

  • Enhanced case management with database-level exclusions.

  • Improved outlier detection using the APP_USER_NAME field for database identification.

 

Active threat detection and analytics

Reduce noise through improved observations and case correlation.

  • Centralized case creation logic provides fewer false positives through improved collaboration between three specialized Guardium threat detection engines: Eagle Eye, Outlier, and Threat Finder.

  • Enhanced identification of encoded and obfuscated payloads, and improved recognition of evasive attack techniques such as blind SQL injection and time-based attacks.

  • Improved outlier anomaly detection by separating how instance count and records affected are learned and evaluated to increase accuracy and clarity.

 

Archive support for NFS

Set up a Network File System (NFS) target for archive workflows through the UI. Additionally, archive catalog entries can be created or updated in the catalog location table by using the GuardAPI commands create_entry_location and update_entry_location. 

 

Database activity monitoring updates

Enhancements to database activity monitoring capabilities include:

  • Support for monitoring the unique identifier (UID) chain while Application TAP (A-TAP) is enabled.

  • Support for exception-related policy rules that use error codes for IBM DataStax Enterprise.

  • guard-config-update script updated to remove dependency on "ed" utility.

  • LD_PRELOAD implementation supports dynamic configuration, allowing for more flexible library loading at runtime.

 

Data streams

Monitor more data sources across hybrid cloud environments.

  • HashiCorp Vault and Microsoft Entra ID authentication support for Azure Event Hubs data streaming.

  • Support for unique database identification for API streaming traffic from multiple subscriptions to a single event hub within Azure Event Hubs.

 

Edge Gateway 2.2 
A scalable, Kubernetes-based service architecture, Edge Gateway now supports ingestion into multiple partitions within the same Aggregator by using Collector ID, and supports monitoring unique identifier (UID) chains.

 

External AI provider integrations

Integrate Guardium with any external AI provider, such as OpenAI, Anthropic, Google Gemini, and Mistral AI, through the GenAI Settings page. Support your generative AI use cases with the AI models that align with your internal standards, while maintaining governance, transparency, and control.

 

Long-term retention 

Enhancements to Guardium long-term retention include new and updated user interfaces for the Setup and Data Lake Report management tools, support for Iceberg REST catalog, and overall data pipeline and optimization improvements.

 

Model Context Protocol support

Support added for the Guardium Model Context Protocol (MCP) server, enabling standardized access to Guardium capabilities for AI agents and removing the need for feature-specific integration code.

 

Policies

Expanded Basic Security Policy now includes standard outlier use cases. New session-level policy rule criteria UID_CHAIN_USER matches against usernames within the unique identifier (UID) chain, allowing policies to trigger based on which users are present in the execution chain leading to a database session.

 

Real-time trust evaluator

The trust evaluator now uses a continuous learning model that incorporates new findings into the scores daily. Status types are now simply WARMING UP, ACTIVE, and IDLE. Although training data for the probability engine is reset with the move to the continuous learning model, training the new model is faster and more stable.

 

Simplified compliance policy discovery
Use a clear, structured, and framework-aligned method to quickly identify supported regulations, standards, and industries, and apply the appropriate monitoring policies with confidence. Improve compliance clarity, accelerate onboarding, strengthen evaluation readiness, and map monitoring results directly to regulatory obligations without requiring deep product expertise.

 

Unified Discovery and Classification
Automatically convert Unified Discovery and Classification (UDC) classifications into Guardium groups and populate the Guardium Asset Inventory to enable regulation-aligned, sensitivity-aware monitoring. This feature delivers complete asset visibility through continuous discovery, classification, and protection.


Universal connector 
New universal connector features and enhancements include:

  • Troubleshooting and health monitoring automatically logs exceptions, errors, status updates, and performance metrics, enabling faster issue identification and resolution.
  • HTTP proxy support for the following UC 2.0 connectors: AWS CloudWatch, Azure Event Hub, and Google Cloud Pub/Sub.
  • HashiCorp Vault integration with UC credentials extended to support AWS Secrets Engine. In addition, the Vault key/value (KV) secrets engine now supports Oracle Unified Audit (OUA)-based connectors.
  • Additional classic UC input plug-in is available for CockroachDB over Syslog.
  • For UC 2.0, additional Azure Event Hub, Capella, and Syslog-based connectors are available: Azure Event Hub connector for Azure Cosmos, Capella connector for Capella, and Syslog connectors for AlloyDB Omni, CockroachDB, and Yugabyte.
  • CockroachDB over Syslog configuration changed significantly for the Kafka-based UC 2.0 architecture. For updated configuration details, see Configuring CockroachDB datasource profiles for Kafka Connect plug-ins.


Two universal connector security updates require action:

  • The Logstash version used for universal connectors is now upgraded to version 9.3.3. This might require configuration changes in your current environment. For more information, see Logstash 9.3.3 upgrade guide.
  • All universal connectors that use certificates must now be reconfigured by providing an encryption password with the ssl_key_passphrase => "${ssl_key_passphrase}" parameter in the input configuration. After you make the change, restart or reinstall your Logstash-based universal connector.


Note: Universal connector (UC) fixes are delivered in cumulative patches separate from Guardium Data Protection appliance bundle patches. When you install Guardium 12.2.3 (GPU 12.0p230), your UC will upgrade to what is included in the GPU only if the UC on the system where you are installing GPU 12.0p230 is older than the UC that is included in GPU 12.0p230. 

Vulnerability Assessment 
Scan databases for vulnerabilities by using the latest benchmarks and data source tests.

  • Assessment Tests for EDB PostgreSQL based on the latest CIS PostgreSQL 17 benchmarks.
  • Data source currency updates: Couchbase 7.6, 8.0, DataStax Cassandra 6.8, and Oracle 26ai (includes on-prem and autonomous cloud).
  • Additional Java and Guardium CAS-based tests for MarkLogic.
  • Support for running Vulnerability Assessment Scanner on Red Hat OpenShift Container Platform.


Linux-UNIX and Windows Agents updates

More information about new features and enhancements to the Configuration Auditing System (CAS), Guardium Installation Manager (GIM), File Activity Monitor (FAM) for Windows (FamMonitor), and Software TAP (S-TAP) agents, see their corresponding release notes: 


Patch updates for the Linux-UNIX and Windows Agents are cumulative; they contain all previous patches for that major version. 

 

Sniffer updates
 

The latest sniffer patch that is included in Guardium 12.2.3 (GPU 12.0p230) is version 12.0p4017 (see release notes). Sniffer patches are cumulative; they contain all previous sniffer patches for that major version.

 
New supported platforms and databases
 

Sniffer

  • CockrochDB 26.1
  • Couchbase 8
  • CouchDB 3.5.1
  • IBM Db2 PureScale 12.1
  • Model Context Protocol
  • TigerGraph 4.2.2

 

Vulnerability Assessment

  • Couchbase 7.6, 8.0
  • DataStax Cassandra 6.8
  • Oracle 26ai (includes on-prem and autonomous cloud)

 

Most supported platforms information is available in the Guardium Supported Datasources matrix. For all other supported platforms and system requirements information, including Vulnerability Assessment, platforms that are supported by External S-TAP, information about IBM i, and hardware or virtual machine requirements, see System Requirements for Guardium 12.2.x.

 
Deprecated commands, platforms, and functionality
 

Deprecated functionality
As of Guardium version 12.2.3 (GPU 12.0p230), universal connector support for EDB Postgres over Kafka and Yugabyte over Kafka is discontinued.  

Guardium version 11.4 end of support
On 30 April 2026, Guardium Data Protection 11.4 reached completion of Extended Support. For more information, see IBM Support Product lifecycle overview

Guardium version 11.5 support transition
On 30 April 2026, Guardium Data Protection 11.5 reached completion of Base Support and transitions to Extended Support. For more information, see IBM Support Product lifecycle overview.

 

Resolved issues 
VersionIssue keySummaryKnown issue (APAR)
12.2.2 (GPU 12.0p220) See release notes for Guardium 12.2.2 (GPU 12.0p220) 
12.2.3 (GPU 12.0p230)GRD-88744Analytic User Feedback report unavailable in Query-Report BuilderDT451550
 GRD-113577Universal collector not receiving logs for Oracle Exadata Cloud Customer (ExaCC) clusterDT460218
 GRD-116456S-TAP shows inactive status on one collector in enterprise load balancing group despite active trafficDT468391
 GRD-116463Certificates stored in cleartext DT469444
 GRD-116782Fixed memory leak issue due to outdated Kerberos librariesDT474725
 GRD-117233Cannot access Guardium with IP address after SAML migrationDT462205
 GRD-117964Deployment health topology shows collectors connected to central manager instead of aggregatorDT468575
 GRD-118618Active Threat Analytics case details page fails to loadDT469091
 GRD-118663Deployment health shows collector aggregation status as "status unavailable"DT469394
 GRD-118761REST API remote source hostname becomes case-sensitive after upgraded from version 11.4DT467870
 GRD-119115VA assessment builder fails with "selectedDataSourceIndex invalid field" errorDT470697
 GRD-119857Universal connector shows fatal error despite normal operationDT469413
 GRD-120358Certificate expiration warning displays 10 months early for snif and tomcat certificatesDT468962
 GRD-120764Collectors missing from Active Threat Analytics DAM outlier mining dashboardDT468402
 GRD-120773OpenSSL updates and build artifacts cleanupDT468509
 GRD-121194Login report shows success for failed login attempts on disabled admin userDT467803
 GRD-121458Add support for kernel 6.17.0-14-generic-x86_64 Ubuntu 24.04.3DT473574
 GRD-121741Large enterprise STAP verification table causes deployment health performance issuesDT469440
 GRD-121826SNMP alerter service stops unexpectedly preventing trap deliveryDT467797
 GRD-122050Kafka node displays incorrect GIM certificate warning when GIM not usedDT469453
 GRD-122240INITIAL_BALANCER_MU_GROUP parameter editable in UI despite being installation-onlyDT468389
 GRD-122297Truncated SQL statements not matching policy rules due to parser errors 
 GRD-122334AWS Kinesis stream discovery fails with IAM instance profile authentication 
 GRD-122489Support custom signed certificates for Kafka nodesDT467859
 GRD-122755Real-time Trust Evaluator displays decommissioned collectors instead of active onesDT473919
 GRD-122867Private key visible in certificateDT470805
 GRD-122895HashiCorp Vault TLS authentication fails with "client certificate must be supplied"DT469445
 GRD-122900Inspection Engine DB_0 captures traffic from incorrect portsDT469392
 GRD-123023Request to suppress large group members in custom VA assessment tests due to Oracle list limitationDT468486
 GRD-123236Remove proxy settings from Qualys VM scanner configurationDT468930
 GRD-123329CAS certificate not regenerated after delete and restore from defaultDT468895
 GRD-123522Inspection Engine unable to discover PostgreSQL (PGaaS) databases automaticallyDT468892
 GRD-123672False positive results from Vulnerability Assessment scans for Microsoft SQL Server CVE testsDT469687
 GRD-123786Multiple managed units show intermittent "unit not responding" in Deployment Health tableDT473163
 GRD-124021Health check 12.0p9997 boot space errorDT468985
 GRD-124115Default 'guardium' user account cannot be deletedDT469430
 GRD-124210ATA dashboard bulk case closure requires duplicate selectionDT474356
 GRD-124291Certificate Management page does not display all managed units with expiring Tomcat alias certificatesDT473616
 GRD-124295Aggregation/Archive Report displays incomplete hostname for central manager backup activitiesDT469390
 GRD-124855A-TAP service activates although no Inspection Engines are configuredDT470737
 GRD-125132Auto-discovery fails to detect Microsoft SQL Server inspection engine on dynamic portDT474476
 GRD-125239guardcli1-9 accounts no longer enforce 'set guiuser' requirement 
 GRD-125578Access manager password reset failureDT471917
 GRD-125668Add environment variables configuration file in S-TAP MustGather 
 GRD-126117Resolved improper session validation by changing the code path that updated the logged in user to perform user logout instead.DT474201
 GRD-126326Old WfpMonitor driver causes loss of network connectivityDT474430
 GRD-126441Computed attribute type defaults to text 
 GRD-126444Incorrect host name displays on Data Restore screen DT474324
 GRD-126561AIX S-TAP: SQL queries fail due to missing 32-bit libraries in a 64-bit environmentDT473492
 GRD-127223Instance name conflicts in S-TAP ControlDT473918
 GRD-127328Tomcat 9.0.118 updateDT474353
 GRD-127898Appliance disk space filling up due to syslog messages 
 
 
Security fixes
VersionIssue keySummaryCVE
12.2.2 (GPU 12.0p220) See release notes for Guardium 12.2.2 (GPU 12.0p220) 
12.2.3 (GPU 12.0p230)GRD-116270PSIRT: PVR0692231 - lz4-java-1.8.0.jar (Publicly disclosed vulnerability found by Scanner) CVE-2025-12183
 GRD-116332PSIRT: PVR0689653 - jersey-client-2.0-m08-1.jar (Publicly disclosed vulnerability found by Scanner)CVE-2025-12383
 GRD-116334PSIRT: PVR0694349 - lz4-1.3.0.jar (Publicly disclosed vulnerability found by Scanner) - Datastreams
CVE-2025-66566
 GRD-116336PSIRT: PVR0693901 - grpc-protobuf-1.28.0.jar (Publicly disclosed vulnerability found by Scanner)CVE-2023-1428
 GRD-116337PSIRT: PVR0694620 - urllib3-1.26.5-py2.py3-none-any.whl (Publicly disclosed vulnerability found by Scanner)CVE-2025-66418, CVE-2025-66471
 GRD-117723PSIRT: PVR0696387 netty-codec-http-4.1.118.Final.jar (Publicly disclosed vulnerability found by Scanner)CVE-2025-67735
 GRD-121329PSIRT: PVR0509482 - bcprov-jdk15on-1.56.jar (Publicly disclosed vulnerability found by Mend)CVE-2024-30172
 GRD-121498PSIRT: PVR0723499, PVR0751861 - jetty-http-10.0.26.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2025-11143, CVE-2026-2332
 GRD-122383PSIRT: PVR0736740 - StateFarm - Pen Testing - path traversal vulnerability 
 GRD-122387PSIRT: PVR0736741 - StateFarm - Pen Testing - Cross-Site Scripting vulnerability 
 GRD-122443PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner)PSIRT-WS-2026-0003
 GRD-122444PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner)PSIRT-WS-2026-0003
 GRD-122445PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner)PSIRT-WS-2026-0003
 GRD-122446PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner)PSIRT-WS-2026-0003
 GRD-122458PSIRT: PVR0736742 - StateFarm - Pen Testing - DOM-based XSS 
 GRD-122461PSIRT: PVR0736743 - StateFarm - Pen Testing - Information Exposure 
 GRD-123384PSIRT: PVR0744608 lodash-4.17.23.tgz and lodash-es-4.17.23.tgz (Publicly disclosed vulnerability found by Scanner)CVE-2025-13465
 GRD-123718PSIRT: PVR0748240, PVR0749376, PVR0758388 - axios-1.13.5.tgz, axios-1.15.0.tgz (Publicly disclosed vulnerability found by mend Scanner)CVE-2025-62718, CVE-2026-40175, CVE-2026-42033, CVE-2026-42034, CVE-2026-42035, CVE-2026-42036, CVE-2026-42037, CVE-2026-42038, CVE-2026-42039, CVE-2026-42040, CVE-2026-42041, CVE-2026-42042, CVE-2026-42043, CVE-2026-42044
 GRD-123721PSIRT: PVR0746405 - kafka-clients-3.9.1.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-35554
 GRD-123742PSIRT: PVR0747300 - cassandra-all-4.0.4.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-27315, CVE-2026-32588
 GRD-124129PSIRT: PVR0752700 - bcpkix-jdk18on-1.78.1.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-5588
 GRD-124257PSIRT: PVR0723499, PVR0751861 - jetty-http-10.0.26.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-2332, CVE-2025-11143
 GRD-124259PSIRT: PVR0723499, PVR0751861 - jetty-http-10.0.26.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2025-11143, CVE-2026-2332
 GRD-124260PSIRT: PVR0755199 - bcpkix-jdk18on-1.78.1.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2025-14813, CVE-2026-0636, CVE-2026-5598
 GRD-124470PSIRT: PVR0754821 - IBM SDK, Java Technology Edition Quarterly CPU - Apr 2026 - Includes Oracle April 2026 CPUCVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007
 GRD-124472PSIRT: PVR0755809 - python_dotenv-1.1.1-py3-none-any.whl (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-28684
 GRD-124474PSIRT: PVR0755487 - kafka-clients-3.9.1.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-33558
 GRD-124616PSIRT: PVR0757062, PVR0757161 - spring-security-config-5.8.16.jar, spring-security-core-5.8.16.jar (Publicly disclosed vulnerability found by MEND Scanner)CVE-2026-22753, CVE-2026-22754, CVE-2026-22746
 GRD-124618PSIRT: PVR0756980 - httpclient5-5.6.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-40542
 GRD-124800PSIRT: PVR0759247 - uuid-11.1.0.tgz (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41907
 GRD-124801PSIRT: PVR0756413 - dompurify-3.3.3.tgz (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41238, CVE-2026-41239, CVE-2026-41240
 GRD-124802PSIRT: PVR0756641 - follow-redirects-1.15.11.tgz (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-40895
 GRD-124804PSIRT: PVR0757824 - postcss-8.5.9.tgz (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41305
 GRD-124978PSIRT: PVR0761523 - postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42198
 GRD-124979PSIRT: PVR0761523 postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42198
 GRD-124981PSIRT: PVR0760981, PVR0763120: libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner)CVE-2026-41603, CVE-2026-43869
 GRD-125002PSIRT:  PVR0760981, PVR0763120: libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner)CVE-2026-41603, CVE-2026-43869
 GRD-125054PSIRT: PVR0762260 - spring-webmvc-5.3.39.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-22745
 GRD-125400PSIRT: PVR0763625 - netty-codec-http-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41417
 GRD-125401PSIRT: PVR0763625 - netty-codec-http-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41417
 GRD-125402PSIRT: PVR0763625 - netty-codec-http-4.2.11.Final.jar(Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41417
 GRD-125687PSIRT: PVR0765189 - vertx-core-4.5.22.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-6860
 GRD-126526PSIRT: PVR0769315 - netty-handler-proxy-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42578
 GRD-126528PSIRT: PVR0770587 - azure-storage-blob-12.6.1.jar (Publicly disclosed vulnerability found by MEND Scanner) CVE-2022-30187
 GRD-126529PSIRT: PVR0771910 - commons-configuration2-2.9.0.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-45205
 GRD-126530PSIRT: PVR0771910 - commons-configuration2-2.9.0.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-45205
 GRD-126531PSIRT: PVR0768851 - netty-codec-dns-4.1.132.Final.jar (Publicly disclosed vulnerability found by Scanner)CVE-2026-42579
 GRD-126532PSIRT: PVR0770872, PVR0768598 - netty-transport-native-epoll-4.1.125.Final.jar , netty-codec-4.1.125.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42577, CVE-2026-42583
 GRD-126533PSIRT: PVR0772995 - ws-8.18.0.tgz (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-45736
 GRD-126534PSIRT: PVR0769001 - netty-codec-http-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587
 GRD-126536PSIRT: PVR0769741 - urllib3-1.26.5-py2.py3-none-any.whl (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-44431
 GRD-127736PSIRT: PVR0776317 - idna-3.10-py3-none-any.whl (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-45409
 GRD-127947PSIRT: PVR0780873 - kafka-clients-4.2.0.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-41115
 GRD-128337PSIRT: PVR0782835 - pyarrow-21.0.0-cp39-cp39-manylinux_2_28_x86_64.whl (Publicly disclosed vulnerability found by MEND Scanner)CVE-2026-25087
 GRD-128941PSIRT: PVR0788629, PVR0788487 - netty-transport-native-epoll-4.2.13.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-45536, CVE-2026-45673, CVE-2026-45674, CVE-2026-47691
 GRD-128944PSIRT: PVR0789460, PVR0788055 - netty-codec-http2-4.1.133.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-50560, CVE-2026-47244, CVE-2026-48043
 GRD-128945PSIRT:  PVR0789174, PVR0787894 - netty-codec-classes-quic-4.2.3.Final.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-50009, CVE-2026-44894
 
 
Known limitations and workarounds
ComponentIssue keySummary
Active Threat Analytics GRD-127081

The Observations filter does not currently use the observation's Last Updated timestamp for filtering. 

Workaround: Adjust the filter time range accordingly to locate the expected observations.

Active Threat Analytics GRD-128327

No data appears in the Grant command execution report for some of the cases having observations from the Eagle Eye engine. 

A fix will be available in an upcoming release.

Active Threat Analytics GRD-128957

When a Threat Finder case is generated the first time for a source, the following visualizations do not load immediately:

  • Source behavior analysis by object
  • Source behavior analysis by applications
  • Source behavior analysis by verbs
  • Sankey charts

Instead, the UI displays "No source behavior analysis found – No records found for this chart" message. These charts only become available after the current hour completes, so you must wait for the current hour to complete to view all the charts. 

Active Threat Analytics GRD-128975

In the upgraded setup, exclusion functionality does not work as expected with the existing exclusion for both Threat Finder (input level) and Correlation Engine (output level). Even when exclusion entries are present in the old ANALYTIC_EXCLUDE_LIST table, input-level exclusions are not applied in Threat Finder and output-level exclusions are not applied in the Correlation Engine. 

Workaround: Disable the existing exclusion entry and then re-enable the exclusion entry. This action moves older exclusion entries to the new table structure and then the exclusion starts working as expected.

Active Threat Analytics GRD-129155

When upgrading a cluster to version 12.2.3 (GPU 12.0p230), existing custom policies created in earlier versions will not migrate successfully. As a result, custom policies that were present before the upgrade will be unavailable after the upgrade is completed. 

Workaround: After upgrading to version 12.2.3 (GPU 12.0p230), manually recreate the custom policies that were configured prior to the upgrade.

Backup and restoreGRD-125220

The values of the following CLI commands are not retained when data is backed up from version 12.2.3 (GPU 12.0p230) and restored in version 12.2.3 (GPU 12.0p230). A fix will be available in an upcoming release.

  • store monitor gdm_statistics
  • store pdf-config orientation
  • store pdf-config size
  • store remotelog max_message_size
  • store timeout fileserver_session
  • store timeout db_connection
  • store system classifier profile
  • store system snif-alerts-facility
  • store system time_server state
  • store monitor custom_db_usage
  • store pdf-config size
  • store pdf-config orientation
  • store system sshd-max-connection

 

The values of the following CLI commands are not retained when data is backed up from version 12.2.2 (GPU 12.0p220) and restored to version 12.2.3 (GPU 12.0p230). A fix will be available in an upcoming release.

  • show system snif-thread-number
  • show pdf-config size
  • show remotelog max_message_size
  • show timeout fileserver_session
  • show timeout db_connection
  • show next_export_static
  • show allow_reinstall
  • show system classifier profile
  • show system scp-ssh-key-mode
  • show archive_static_table
  • show system time_server state
  • show monitor custom_db_usage
  • support show snif-debug
  • show pdf-config multilanguage_support
  • show system sshd-max-connection
  • support show tcpdump
  • grdapi get_quick_search_info 
Long-term retentionGRD-129104

When running DataLake setup commands (store datalake all_in_one, store datalake query_engine, store datalake query_worker, or store datalake metastore) on a fresh installation, a warning message incorrectly appears stating "WARNING: Existing datalake configuration found in runtime directory" even when no actual configuration exists. This occurs because the validation checks for the presence of the runtime directory rather than actual configuration files. The warning is misleading but does not prevent successful setup. 

Workaround: When you see the warning "WARNING: Existing datalake configuration found in runtime directory" during a fresh installation, type 'yes' when prompted to continue. This is safe to do and will not cause any issues. The warning is informational only and does not indicate an actual problem with your installation. The setup will proceed normally and create a new configuration.

Long-term retentionGRD-129205

Currently, the grdapi configure_complete_cold_storage command will not check whether the datalake service is stored on the app-node. If a user accidentally put the wrong app node in as the catalog endpoint, the GuardAPI does not detect that and rejects the endpoint. 

A fix will be available in an upcoming release.

Long-term retentionGRD-129360, GRD-129583

When a Guardium central manager running versions 12.2.1 (GPU 12.0p210) or 12.2.2 (GPU 12.0p220) with a long-term retention configuration (such as Data lake patch 12.0p80111) is upgraded to a later Guardium version, such as Guardium 12.2.3 (GPU 12.0p230), the long-term retention datamarts in the collector might cease to work. 

Workaround: After upgrading the central manager, run the following two GuardAPI commands to disable and re-enable the long-term retention streaming:

grdapi configure_cold_storage_data_streaming action=disable coldStorageName=datalake 

grdapi configure_cold_storage_data_streaming action=enable coldStorageName=datalake 

Long-term retentionGRD-129535, GRD-129538

When an appliance configured with long-term retention is restarted, the long-term retention services do not start automatically. 

Workaround: On the appliance configured with long-term retention, run the following CLI command: store datalake service start 

Long-term retentionGRD-129557

When an appliance configured with long-term retention is restarted after backup/restore, the long-term retention services do not start automatically. 

Contact IBM Support for assistance.

OutliersGRD-123891

Outlier analysis stops working after upgrading from versions 12.2 (GPU 12.0p200) or 12.2.1 (GPU 12.0p210) to versions 12.2.2 (GPU 12.0p220) or 12.2.3 (GPU 12.0p230) on central manager-aggregator deployments. 

Workaround: After upgrading from version 12.2 (GPU 12.0p200) to 12.2.1 (GPU 12.0p210), or version 12.2.2 (GPU 12.0p220) to 12.2.3 (GPU 12.0p230), disable and re-enable outlier analysis on the central manager-aggregator deployment to recreate the data mart (DM) header entries required for proper outlier processing.

OutliersGRD-127838

Full SQL report does not show respective data for Outlier observations. 

A fix will be available in an upcoming release.

Unified Discovery and ClassificationGRD-127679

Within the Unified Discovery and Classification UI, the Edit option is missing for Target group. 

Workaround: Delete the group and create a new group to add Sensitivities and Regulations of choice to update or edit the group.

Unified Discovery and ClassificationGRD-129266

The Regulations drop-down screen jumps rapidly. 

Workaround: Checking any of the regulations, such as CCPA or GDPR, stops the screen from jumping.

UpgradeGRD-114277

After upgrading to version 12.2.3 (GPU 12.0p230) from version 12.2.2 (GPU 12.0p220), the values of the CLI command show aggregator static_data are not retained. 

A fix will be available in an upcoming release.

Universal connectorGRD-127570To prevent Arrow format errors ("sun.misc.Unsafe or DirectByteBuffer not available") due to Java updates, add the JDBC_QUERY_RESULT_FORMAT=JSON parameter to the Snowflake UC JDBC connection strings. For more information, refer to the updated Snowflake JDBC configuration file.

 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.2.0"}]

Document Information

Modified date:
29 July 2026

UID

ibm17277083