Release Notes
Abstract
This technical note provides guidance for installing IBM Guardium Data Protection 12.2.3, including any new features or enhancements, resolved or known issues, or associated notices for Guardium patch update (GPU) 12.0p230, Edge patch 12.0p15003, Gen AI patch 12.0p80020, and Data lake (long-term retention) patch 12.0p80103.
Content
On Passport Advantage, you can find the Guardium Product Image - ISO file, licenses, product keys, and manuals. You can download only the products that your site is entitled. If you need assistance to find or download a product from the Passport Advantage site, contact the Passport Advantage team at 800-978-2246 (8:00 AM - 8:00 PM ET) or by email at paonline@us.ibm.com.
On Fix Central, you can find upgrades, Guardium Patch Update (GPU) files, individual patches, and the current versions of database agents, such as Software TAP (S-TAP) and Guardium Installation Manager (GIM). If you need assistance to find a product on Fix Central, contact IBM Support.
Install Guardium 12.2.3
Guardium 12.2.3 is available as an ISO product image on Passport Advantage. If the downloaded package is in .zip format, extract it outside of the Guardium appliance before you upload or install it. Review the latest version of these release notes just before you install. Install Guardium across all the appliances, such as the central manager, aggregators, and collectors. For detailed steps, see Installing your Guardium Data Protection system.
Before you upgrade, confirm that your appliance meets the minimum requirements. Upgrade your firmware to the latest versions provided by your vendor. If you use a Guardium appliance, check Fix Central for the latest firmware.
You can upgrade to Guardium 12.2.3 (GPU 12.0p230) from Guardium systems that are running on version 12.2.0 (GPU 12.0p200, see release notes). The best approach for upgrading Guardium depends on the version you are upgrading from, the hardware of your system, and any special partitioning requirements you might have. See Identifying the correct upgrade path to review upgrade scenarios and identify the correct upgrade path for your Guardium systems. Review the latest version of these release notes just before you install.
Note: The Guardium system will restart during the upgrade process for all of the patch installations, so schedule the upgrades in batches during low database traffic times to minimize audit gaps. Do not reboot the appliance while the patch installations are in progress. Contact IBM Support if there is an issue with patch installation.
- Guardium Data Protection 12.0p200 (see release notes)
- The latest Guardium Data Protection health check patch 12.0p9997
Ad hoc patches
When you install GPU 12.0p230 on the central manager, the following ad hoc patches also deploy on the corresponding managed units to allow existing functionality to continue to work properly even if the managed units stay on older patch levels for an extended period of time.
- 12.0p1044 - Add column RECORDS_AFFECTED_ONLY to DATAMART.AGG_ANALYTIC_INPUT table
- 12.0p1045 - Update Solr Certificate
- 12.0p1145 - Add column ASPECT_LEVEL to DATAMART.AGG_ANALYTIC_INPUT table
Feature flags
Guardium supports feature flags to help you control when new capabilities are activated in your environment. For Guardium 12.2.3, the following feature patches are available in Fix Central for download/installation: Edge patch 12.0p15003, Gen AI patch 12.0p80020, and Data lake (long-term retention) patch 12.0p80103. For more information, see Applying feature flags.
Single stream agent releases
Most of the Linux-UNIX and Windows agents for Guardium Data Protection versions 12.0 and later are now released in a single stream. This simplifies maintenance, reduces version divergence, and ensures consistent feature and fix availability across all supported 12.x environments. For more information, see Single-stream agent releases.
Special Guardium Database Protection Service update (for Vulnerability Assessment only)
A special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, which is available for download from Fix Central, must be applied after you upgrade to Guardium 12.2.3 (GPU 12.0p230) from previous versions. See release notes for detailed file information. Be sure to also check Fix Central for the latest Rapid Response DPS release and apply it after uploading the Special DPS file.
Automated patch downloads
Keep Guardium continuously up to date by letting the service automatically monitor Fix Central for new patches and download them as soon as they become available so you can schedule the installation. Easily enabled through the CLI to reduce manual effort and significantly accelerate upgrade cycles. Note: Requires connectivity to the internet either directly or through an HTTP proxy.
Active threat analytics UI
Streamline onboarding and accelerate risk detection and response with enhanced usability.
Modernized setup page to simplify case configurations.
Automatic case closure options.
Enhanced exclusion criteria with additional parameters and recurrence-based filtering capabilities.
Caching of case summaries and policy explanations in the database improves responsiveness and reduces wait times to regenerate content.
Server-side pagination for the Active threat analytics cases table improves performance when working with large case volumes, enabling efficient navigation and search across all cases.
What this means feature uses generative AI to explain policy rule violations, helping you understand what triggered violations without interpreting policy builder configurations.
Active threat analytics for IBM Db2 z/OS
Gain more granular analysis of database-level threat detection support for IBM Db2 z/OS environments.
18 updated reports with database-level filtering capabilities.
8 new reports for database-specific threat analysis.
Enhanced case management with database-level exclusions.
Improved outlier detection using the APP_USER_NAME field for database identification.
Active threat detection and analytics
Reduce noise through improved observations and case correlation.
Centralized case creation logic provides fewer false positives through improved collaboration between three specialized Guardium threat detection engines: Eagle Eye, Outlier, and Threat Finder.
Enhanced identification of encoded and obfuscated payloads, and improved recognition of evasive attack techniques such as blind SQL injection and time-based attacks.
Improved outlier anomaly detection by separating how instance count and records affected are learned and evaluated to increase accuracy and clarity.
Archive support for NFS
Set up a Network File System (NFS) target for archive workflows through the UI. Additionally, archive catalog entries can be created or updated in the catalog location table by using the GuardAPI commands create_entry_location and update_entry_location.
Database activity monitoring updates
Enhancements to database activity monitoring capabilities include:
Support for monitoring the unique identifier (UID) chain while Application TAP (A-TAP) is enabled.
Support for exception-related policy rules that use error codes for IBM DataStax Enterprise.
guard-config-update script updated to remove dependency on "ed" utility.
LD_PRELOAD implementation supports dynamic configuration, allowing for more flexible library loading at runtime.
Data streams
Monitor more data sources across hybrid cloud environments.
HashiCorp Vault and Microsoft Entra ID authentication support for Azure Event Hubs data streaming.
Support for unique database identification for API streaming traffic from multiple subscriptions to a single event hub within Azure Event Hubs.
Edge Gateway 2.2
A scalable, Kubernetes-based service architecture, Edge Gateway now supports ingestion into multiple partitions within the same Aggregator by using Collector ID, and supports monitoring unique identifier (UID) chains.
External AI provider integrations
Integrate Guardium with any external AI provider, such as OpenAI, Anthropic, Google Gemini, and Mistral AI, through the GenAI Settings page. Support your generative AI use cases with the AI models that align with your internal standards, while maintaining governance, transparency, and control.
Long-term retention
Enhancements to Guardium long-term retention include new and updated user interfaces for the Setup and Data Lake Report management tools, support for Iceberg REST catalog, and overall data pipeline and optimization improvements.
Model Context Protocol support
Support added for the Guardium Model Context Protocol (MCP) server, enabling standardized access to Guardium capabilities for AI agents and removing the need for feature-specific integration code.
Policies
Expanded Basic Security Policy now includes standard outlier use cases. New session-level policy rule criteria UID_CHAIN_USER matches against usernames within the unique identifier (UID) chain, allowing policies to trigger based on which users are present in the execution chain leading to a database session.
Real-time trust evaluator
The trust evaluator now uses a continuous learning model that incorporates new findings into the scores daily. Status types are now simply WARMING UP, ACTIVE, and IDLE. Although training data for the probability engine is reset with the move to the continuous learning model, training the new model is faster and more stable.
Simplified compliance policy discovery
Use a clear, structured, and framework-aligned method to quickly identify supported regulations, standards, and industries, and apply the appropriate monitoring policies with confidence. Improve compliance clarity, accelerate onboarding, strengthen evaluation readiness, and map monitoring results directly to regulatory obligations without requiring deep product expertise.
Unified Discovery and Classification
Automatically convert Unified Discovery and Classification (UDC) classifications into Guardium groups and populate the Guardium Asset Inventory to enable regulation-aligned, sensitivity-aware monitoring. This feature delivers complete asset visibility through continuous discovery, classification, and protection.
Universal connector
New universal connector features and enhancements include:
- Troubleshooting and health monitoring automatically logs exceptions, errors, status updates, and performance metrics, enabling faster issue identification and resolution.
- HTTP proxy support for the following UC 2.0 connectors: AWS CloudWatch, Azure Event Hub, and Google Cloud Pub/Sub.
- HashiCorp Vault integration with UC credentials extended to support AWS Secrets Engine. In addition, the Vault key/value (KV) secrets engine now supports Oracle Unified Audit (OUA)-based connectors.
- Additional classic UC input plug-in is available for CockroachDB over Syslog.
- For UC 2.0, additional Azure Event Hub, Capella, and Syslog-based connectors are available: Azure Event Hub connector for Azure Cosmos, Capella connector for Capella, and Syslog connectors for AlloyDB Omni, CockroachDB, and Yugabyte.
CockroachDB over Syslog configuration changed significantly for the Kafka-based UC 2.0 architecture. For updated configuration details, seeConfiguring CockroachDB datasource profiles for Kafka Connect plug-ins.
Two universal connector security updates require action:
- The Logstash version used for universal connectors is now upgraded to version 9.3.3. This might require configuration changes in your current environment. For more information, see Logstash 9.3.3 upgrade guide.
- All universal connectors that use certificates must now be reconfigured by providing an encryption password with the
ssl_key_passphrase => "${ssl_key_passphrase}"parameter in the input configuration. After you make the change, restart or reinstall your Logstash-based universal connector.
Note: Universal connector (UC) fixes are delivered in cumulative patches separate from Guardium Data Protection appliance bundle patches. When you install Guardium 12.2.3 (GPU 12.0p230), your UC will upgrade to what is included in the GPU only if the UC on the system where you are installing GPU 12.0p230 is older than the UC that is included in GPU 12.0p230.
Vulnerability Assessment
Scan databases for vulnerabilities by using the latest benchmarks and data source tests.
- Assessment Tests for EDB PostgreSQL based on the latest CIS PostgreSQL 17 benchmarks.
- Data source currency updates: Couchbase 7.6, 8.0, DataStax Cassandra 6.8, and Oracle 26ai (includes on-prem and autonomous cloud).
- Additional Java and Guardium CAS-based tests for MarkLogic.
- Support for running Vulnerability Assessment Scanner on Red Hat OpenShift Container Platform.
Linux-UNIX and Windows Agents updates
More information about new features and enhancements to the Configuration Auditing System (CAS), Guardium Installation Manager (GIM), File Activity Monitor (FAM) for Windows (FamMonitor), and Software TAP (S-TAP) agents, see their corresponding release notes:
- Linux-UNIX CAS 12.x.p101 r124239: https://www.ibm.com/support/pages/node/7278165
- Linux-UNIX GIM 12.x.p101 r124239: https://www.ibm.com/support/pages/node/7278164
- Linux-UNIX S-TAP 12.x.p101 r124239: https://www.ibm.com/support/pages/node/7278163
- Windows CAS 12.x.p100 r120203321: https://www.ibm.com/support/pages/node/7278221
- Windows FamMonitor 12.x.p100 r120203321: https://www.ibm.com/support/pages/node/7278231
- Windows GIM 12.xp100 r120203321: https://www.ibm.com/support/pages/node/7278232
- Windows S-TAP 12.xp100 r120203321: https://www.ibm.com/support/pages/node/7278217
Patch updates for the Linux-UNIX and Windows Agents are cumulative; they contain all previous patches for that major version.
Sniffer updates
The latest sniffer patch that is included in Guardium 12.2.3 (GPU 12.0p230) is version 12.0p4017 (see release notes). Sniffer patches are cumulative; they contain all previous sniffer patches for that major version.
Sniffer
- CockrochDB 26.1
- Couchbase 8
- CouchDB 3.5.1
- IBM Db2 PureScale 12.1
- Model Context Protocol
- TigerGraph 4.2.2
Vulnerability Assessment
- Couchbase 7.6, 8.0
- DataStax Cassandra 6.8
- Oracle 26ai (includes on-prem and autonomous cloud)
Most supported platforms information is available in the Guardium Supported Datasources matrix. For all other supported platforms and system requirements information, including Vulnerability Assessment, platforms that are supported by External S-TAP, information about IBM i, and hardware or virtual machine requirements, see System Requirements for Guardium 12.2.x.
Deprecated functionality
As of Guardium version 12.2.3 (GPU 12.0p230), universal connector support for EDB Postgres over Kafka and Yugabyte over Kafka is discontinued.
Guardium version 11.4 end of support
On 30 April 2026, Guardium Data Protection 11.4 reached completion of Extended Support. For more information, see IBM Support Product lifecycle overview.
Guardium version 11.5 support transition
On 30 April 2026, Guardium Data Protection 11.5 reached completion of Base Support and transitions to Extended Support. For more information, see IBM Support Product lifecycle overview.
| Version | Issue key | Summary | Known issue (APAR) |
|---|---|---|---|
| 12.2.2 (GPU 12.0p220) | See release notes for Guardium 12.2.2 (GPU 12.0p220) | ||
| 12.2.3 (GPU 12.0p230) | GRD-88744 | Analytic User Feedback report unavailable in Query-Report Builder | DT451550 |
| GRD-113577 | Universal collector not receiving logs for Oracle Exadata Cloud Customer (ExaCC) cluster | DT460218 | |
| GRD-116456 | S-TAP shows inactive status on one collector in enterprise load balancing group despite active traffic | DT468391 | |
| GRD-116463 | Certificates stored in cleartext | DT469444 | |
| GRD-116782 | Fixed memory leak issue due to outdated Kerberos libraries | DT474725 | |
| GRD-117233 | Cannot access Guardium with IP address after SAML migration | DT462205 | |
| GRD-117964 | Deployment health topology shows collectors connected to central manager instead of aggregator | DT468575 | |
| GRD-118618 | Active Threat Analytics case details page fails to load | DT469091 | |
| GRD-118663 | Deployment health shows collector aggregation status as "status unavailable" | DT469394 | |
| GRD-118761 | REST API remote source hostname becomes case-sensitive after upgraded from version 11.4 | DT467870 | |
| GRD-119115 | VA assessment builder fails with "selectedDataSourceIndex invalid field" error | DT470697 | |
| GRD-119857 | Universal connector shows fatal error despite normal operation | DT469413 | |
| GRD-120358 | Certificate expiration warning displays 10 months early for snif and tomcat certificates | DT468962 | |
| GRD-120764 | Collectors missing from Active Threat Analytics DAM outlier mining dashboard | DT468402 | |
| GRD-120773 | OpenSSL updates and build artifacts cleanup | DT468509 | |
| GRD-121194 | Login report shows success for failed login attempts on disabled admin user | DT467803 | |
| GRD-121458 | Add support for kernel 6.17.0-14-generic-x86_64 Ubuntu 24.04.3 | DT473574 | |
| GRD-121741 | Large enterprise STAP verification table causes deployment health performance issues | DT469440 | |
| GRD-121826 | SNMP alerter service stops unexpectedly preventing trap delivery | DT467797 | |
| GRD-122050 | Kafka node displays incorrect GIM certificate warning when GIM not used | DT469453 | |
| GRD-122240 | INITIAL_BALANCER_MU_GROUP parameter editable in UI despite being installation-only | DT468389 | |
| GRD-122297 | Truncated SQL statements not matching policy rules due to parser errors | ||
| GRD-122334 | AWS Kinesis stream discovery fails with IAM instance profile authentication | ||
| GRD-122489 | Support custom signed certificates for Kafka nodes | DT467859 | |
| GRD-122755 | Real-time Trust Evaluator displays decommissioned collectors instead of active ones | DT473919 | |
| GRD-122867 | Private key visible in certificate | DT470805 | |
| GRD-122895 | HashiCorp Vault TLS authentication fails with "client certificate must be supplied" | DT469445 | |
| GRD-122900 | Inspection Engine DB_0 captures traffic from incorrect ports | DT469392 | |
| GRD-123023 | Request to suppress large group members in custom VA assessment tests due to Oracle list limitation | DT468486 | |
| GRD-123236 | Remove proxy settings from Qualys VM scanner configuration | DT468930 | |
| GRD-123329 | CAS certificate not regenerated after delete and restore from default | DT468895 | |
| GRD-123522 | Inspection Engine unable to discover PostgreSQL (PGaaS) databases automatically | DT468892 | |
| GRD-123672 | False positive results from Vulnerability Assessment scans for Microsoft SQL Server CVE tests | DT469687 | |
| GRD-123786 | Multiple managed units show intermittent "unit not responding" in Deployment Health table | DT473163 | |
| GRD-124021 | Health check 12.0p9997 boot space error | DT468985 | |
| GRD-124115 | Default 'guardium' user account cannot be deleted | DT469430 | |
| GRD-124210 | ATA dashboard bulk case closure requires duplicate selection | DT474356 | |
| GRD-124291 | Certificate Management page does not display all managed units with expiring Tomcat alias certificates | DT473616 | |
| GRD-124295 | Aggregation/Archive Report displays incomplete hostname for central manager backup activities | DT469390 | |
| GRD-124855 | A-TAP service activates although no Inspection Engines are configured | DT470737 | |
| GRD-125132 | Auto-discovery fails to detect Microsoft SQL Server inspection engine on dynamic port | DT474476 | |
| GRD-125239 | guardcli1-9 accounts no longer enforce 'set guiuser' requirement | ||
| GRD-125578 | Access manager password reset failure | DT471917 | |
| GRD-125668 | Add environment variables configuration file in S-TAP MustGather | ||
| GRD-126117 | Resolved improper session validation by changing the code path that updated the logged in user to perform user logout instead. | DT474201 | |
| GRD-126326 | Old WfpMonitor driver causes loss of network connectivity | DT474430 | |
| GRD-126441 | Computed attribute type defaults to text | ||
| GRD-126444 | Incorrect host name displays on Data Restore screen | DT474324 | |
| GRD-126561 | AIX S-TAP: SQL queries fail due to missing 32-bit libraries in a 64-bit environment | DT473492 | |
| GRD-127223 | Instance name conflicts in S-TAP Control | DT473918 | |
| GRD-127328 | Tomcat 9.0.118 update | DT474353 | |
| GRD-127898 | Appliance disk space filling up due to syslog messages |
| Version | Issue key | Summary | CVE |
|---|---|---|---|
| 12.2.2 (GPU 12.0p220) | See release notes for Guardium 12.2.2 (GPU 12.0p220) | ||
| 12.2.3 (GPU 12.0p230) | GRD-116270 | PSIRT: PVR0692231 - lz4-java-1.8.0.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2025-12183 |
| GRD-116332 | PSIRT: PVR0689653 - jersey-client-2.0-m08-1.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2025-12383 | |
| GRD-116334 | PSIRT: PVR0694349 - lz4-1.3.0.jar (Publicly disclosed vulnerability found by Scanner) - Datastreams | CVE-2025-66566 | |
| GRD-116336 | PSIRT: PVR0693901 - grpc-protobuf-1.28.0.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2023-1428 | |
| GRD-116337 | PSIRT: PVR0694620 - urllib3-1.26.5-py2.py3-none-any.whl (Publicly disclosed vulnerability found by Scanner) | CVE-2025-66418, CVE-2025-66471 | |
| GRD-117723 | PSIRT: PVR0696387 netty-codec-http-4.1.118.Final.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2025-67735 | |
| GRD-121329 | PSIRT: PVR0509482 - bcprov-jdk15on-1.56.jar (Publicly disclosed vulnerability found by Mend) | CVE-2024-30172 | |
| GRD-121498 | PSIRT: PVR0723499, PVR0751861 - jetty-http-10.0.26.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2025-11143, CVE-2026-2332 | |
| GRD-122383 | PSIRT: PVR0736740 - StateFarm - Pen Testing - path traversal vulnerability | ||
| GRD-122387 | PSIRT: PVR0736741 - StateFarm - Pen Testing - Cross-Site Scripting vulnerability | ||
| GRD-122443 | PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner) | PSIRT-WS-2026-0003 | |
| GRD-122444 | PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner) | PSIRT-WS-2026-0003 | |
| GRD-122445 | PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner) | PSIRT-WS-2026-0003 | |
| GRD-122446 | PSIRT: PVR0730977: jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner) | PSIRT-WS-2026-0003 | |
| GRD-122458 | PSIRT: PVR0736742 - StateFarm - Pen Testing - DOM-based XSS | ||
| GRD-122461 | PSIRT: PVR0736743 - StateFarm - Pen Testing - Information Exposure | ||
| GRD-123384 | PSIRT: PVR0744608 lodash-4.17.23.tgz and lodash-es-4.17.23.tgz (Publicly disclosed vulnerability found by Scanner) | CVE-2025-13465 | |
| GRD-123718 | PSIRT: PVR0748240, PVR0749376, PVR0758388 - axios-1.13.5.tgz, axios-1.15.0.tgz (Publicly disclosed vulnerability found by mend Scanner) | CVE-2025-62718, CVE-2026-40175, CVE-2026-42033, CVE-2026-42034, CVE-2026-42035, CVE-2026-42036, CVE-2026-42037, CVE-2026-42038, CVE-2026-42039, CVE-2026-42040, CVE-2026-42041, CVE-2026-42042, CVE-2026-42043, CVE-2026-42044 | |
| GRD-123721 | PSIRT: PVR0746405 - kafka-clients-3.9.1.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-35554 | |
| GRD-123742 | PSIRT: PVR0747300 - cassandra-all-4.0.4.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-27315, CVE-2026-32588 | |
| GRD-124129 | PSIRT: PVR0752700 - bcpkix-jdk18on-1.78.1.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-5588 | |
| GRD-124257 | PSIRT: PVR0723499, PVR0751861 - jetty-http-10.0.26.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-2332, CVE-2025-11143 | |
| GRD-124259 | PSIRT: PVR0723499, PVR0751861 - jetty-http-10.0.26.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2025-11143, CVE-2026-2332 | |
| GRD-124260 | PSIRT: PVR0755199 - bcpkix-jdk18on-1.78.1.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2025-14813, CVE-2026-0636, CVE-2026-5598 | |
| GRD-124470 | PSIRT: PVR0754821 - IBM SDK, Java Technology Edition Quarterly CPU - Apr 2026 - Includes Oracle April 2026 CPU | CVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007 | |
| GRD-124472 | PSIRT: PVR0755809 - python_dotenv-1.1.1-py3-none-any.whl (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-28684 | |
| GRD-124474 | PSIRT: PVR0755487 - kafka-clients-3.9.1.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-33558 | |
| GRD-124616 | PSIRT: PVR0757062, PVR0757161 - spring-security-config-5.8.16.jar, spring-security-core-5.8.16.jar (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2026-22753, CVE-2026-22754, CVE-2026-22746 | |
| GRD-124618 | PSIRT: PVR0756980 - httpclient5-5.6.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-40542 | |
| GRD-124800 | PSIRT: PVR0759247 - uuid-11.1.0.tgz (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41907 | |
| GRD-124801 | PSIRT: PVR0756413 - dompurify-3.3.3.tgz (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41238, CVE-2026-41239, CVE-2026-41240 | |
| GRD-124802 | PSIRT: PVR0756641 - follow-redirects-1.15.11.tgz (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-40895 | |
| GRD-124804 | PSIRT: PVR0757824 - postcss-8.5.9.tgz (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41305 | |
| GRD-124978 | PSIRT: PVR0761523 - postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42198 | |
| GRD-124979 | PSIRT: PVR0761523 postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42198 | |
| GRD-124981 | PSIRT: PVR0760981, PVR0763120: libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2026-41603, CVE-2026-43869 | |
| GRD-125002 | PSIRT: PVR0760981, PVR0763120: libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2026-41603, CVE-2026-43869 | |
| GRD-125054 | PSIRT: PVR0762260 - spring-webmvc-5.3.39.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-22745 | |
| GRD-125400 | PSIRT: PVR0763625 - netty-codec-http-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41417 | |
| GRD-125401 | PSIRT: PVR0763625 - netty-codec-http-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41417 | |
| GRD-125402 | PSIRT: PVR0763625 - netty-codec-http-4.2.11.Final.jar(Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41417 | |
| GRD-125687 | PSIRT: PVR0765189 - vertx-core-4.5.22.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-6860 | |
| GRD-126526 | PSIRT: PVR0769315 - netty-handler-proxy-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42578 | |
| GRD-126528 | PSIRT: PVR0770587 - azure-storage-blob-12.6.1.jar (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2022-30187 | |
| GRD-126529 | PSIRT: PVR0771910 - commons-configuration2-2.9.0.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-45205 | |
| GRD-126530 | PSIRT: PVR0771910 - commons-configuration2-2.9.0.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-45205 | |
| GRD-126531 | PSIRT: PVR0768851 - netty-codec-dns-4.1.132.Final.jar (Publicly disclosed vulnerability found by Scanner) | CVE-2026-42579 | |
| GRD-126532 | PSIRT: PVR0770872, PVR0768598 - netty-transport-native-epoll-4.1.125.Final.jar , netty-codec-4.1.125.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42577, CVE-2026-42583 | |
| GRD-126533 | PSIRT: PVR0772995 - ws-8.18.0.tgz (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-45736 | |
| GRD-126534 | PSIRT: PVR0769001 - netty-codec-http-4.1.132.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587 | |
| GRD-126536 | PSIRT: PVR0769741 - urllib3-1.26.5-py2.py3-none-any.whl (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-44431 | |
| GRD-127736 | PSIRT: PVR0776317 - idna-3.10-py3-none-any.whl (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-45409 | |
| GRD-127947 | PSIRT: PVR0780873 - kafka-clients-4.2.0.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-41115 | |
| GRD-128337 | PSIRT: PVR0782835 - pyarrow-21.0.0-cp39-cp39-manylinux_2_28_x86_64.whl (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2026-25087 | |
| GRD-128941 | PSIRT: PVR0788629, PVR0788487 - netty-transport-native-epoll-4.2.13.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-45536, CVE-2026-45673, CVE-2026-45674, CVE-2026-47691 | |
| GRD-128944 | PSIRT: PVR0789460, PVR0788055 - netty-codec-http2-4.1.133.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-50560, CVE-2026-47244, CVE-2026-48043 | |
| GRD-128945 | PSIRT: PVR0789174, PVR0787894 - netty-codec-classes-quic-4.2.3.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-50009, CVE-2026-44894 |
| Component | Issue key | Summary |
|---|---|---|
| Active Threat Analytics | GRD-127081 | The Observations filter does not currently use the observation's Last Updated timestamp for filtering. Workaround: Adjust the filter time range accordingly to locate the expected observations. |
| Active Threat Analytics | GRD-128327 | No data appears in the Grant command execution report for some of the cases having observations from the Eagle Eye engine. A fix will be available in an upcoming release. |
| Active Threat Analytics | GRD-128957 | When a Threat Finder case is generated the first time for a source, the following visualizations do not load immediately:
Instead, the UI displays "No source behavior analysis found – No records found for this chart" message. These charts only become available after the current hour completes, so you must wait for the current hour to complete to view all the charts. |
| Active Threat Analytics | GRD-128975 | In the upgraded setup, exclusion functionality does not work as expected with the existing exclusion for both Threat Finder (input level) and Correlation Engine (output level). Even when exclusion entries are present in the old ANALYTIC_EXCLUDE_LIST table, input-level exclusions are not applied in Threat Finder and output-level exclusions are not applied in the Correlation Engine. Workaround: Disable the existing exclusion entry and then re-enable the exclusion entry. This action moves older exclusion entries to the new table structure and then the exclusion starts working as expected. |
| Active Threat Analytics | GRD-129155 | When upgrading a cluster to version 12.2.3 (GPU 12.0p230), existing custom policies created in earlier versions will not migrate successfully. As a result, custom policies that were present before the upgrade will be unavailable after the upgrade is completed. Workaround: After upgrading to version 12.2.3 (GPU 12.0p230), manually recreate the custom policies that were configured prior to the upgrade. |
| Backup and restore | GRD-125220 | The values of the following CLI commands are not retained when data is backed up from version 12.2.3 (GPU 12.0p230) and restored in version 12.2.3 (GPU 12.0p230). A fix will be available in an upcoming release.
The values of the following CLI commands are not retained when data is backed up from version 12.2.2 (GPU 12.0p220) and restored to version 12.2.3 (GPU 12.0p230). A fix will be available in an upcoming release.
|
| Long-term retention | GRD-129104 | When running DataLake setup commands (store datalake all_in_one, store datalake query_engine, store datalake query_worker, or store datalake metastore) on a fresh installation, a warning message incorrectly appears stating "WARNING: Existing datalake configuration found in runtime directory" even when no actual configuration exists. This occurs because the validation checks for the presence of the runtime directory rather than actual configuration files. The warning is misleading but does not prevent successful setup. Workaround: When you see the warning "WARNING: Existing datalake configuration found in runtime directory" during a fresh installation, type 'yes' when prompted to continue. This is safe to do and will not cause any issues. The warning is informational only and does not indicate an actual problem with your installation. The setup will proceed normally and create a new configuration. |
| Long-term retention | GRD-129205 | Currently, the grdapi configure_complete_cold_storage command will not check whether the datalake service is stored on the app-node. If a user accidentally put the wrong app node in as the catalog endpoint, the GuardAPI does not detect that and rejects the endpoint. A fix will be available in an upcoming release. |
| Long-term retention | GRD-129360, GRD-129583 | When a Guardium central manager running versions 12.2.1 (GPU 12.0p210) or 12.2.2 (GPU 12.0p220) with a long-term retention configuration (such as Data lake patch 12.0p80111) is upgraded to a later Guardium version, such as Guardium 12.2.3 (GPU 12.0p230), the long-term retention datamarts in the collector might cease to work. Workaround: After upgrading the central manager, run the following two GuardAPI commands to disable and re-enable the long-term retention streaming: grdapi configure_cold_storage_data_streaming action=disable coldStorageName=datalake grdapi configure_cold_storage_data_streaming action=enable coldStorageName=datalake |
| Long-term retention | GRD-129535, GRD-129538 | When an appliance configured with long-term retention is restarted, the long-term retention services do not start automatically. Workaround: On the appliance configured with long-term retention, run the following CLI command: store datalake service start |
| Long-term retention | GRD-129557 | When an appliance configured with long-term retention is restarted after backup/restore, the long-term retention services do not start automatically. Contact IBM Support for assistance. |
| Outliers | GRD-123891 | Outlier analysis stops working after upgrading from versions 12.2 (GPU 12.0p200) or 12.2.1 (GPU 12.0p210) to versions 12.2.2 (GPU 12.0p220) or 12.2.3 (GPU 12.0p230) on central manager-aggregator deployments. Workaround: After upgrading from version 12.2 (GPU 12.0p200) to 12.2.1 (GPU 12.0p210), or version 12.2.2 (GPU 12.0p220) to 12.2.3 (GPU 12.0p230), disable and re-enable outlier analysis on the central manager-aggregator deployment to recreate the data mart (DM) header entries required for proper outlier processing. |
| Outliers | GRD-127838 | Full SQL report does not show respective data for Outlier observations. A fix will be available in an upcoming release. |
| Unified Discovery and Classification | GRD-127679 | Within the Unified Discovery and Classification UI, the Edit option is missing for Target group. Workaround: Delete the group and create a new group to add Sensitivities and Regulations of choice to update or edit the group. |
| Unified Discovery and Classification | GRD-129266 | The Regulations drop-down screen jumps rapidly. Workaround: Checking any of the regulations, such as CCPA or GDPR, stops the screen from jumping. |
| Upgrade | GRD-114277 | After upgrading to version 12.2.3 (GPU 12.0p230) from version 12.2.2 (GPU 12.0p220), the values of the CLI command show aggregator static_data are not retained. A fix will be available in an upcoming release. |
| Universal connector | GRD-127570 | To prevent Arrow format errors ("sun.misc.Unsafe or DirectByteBuffer not available") due to Java updates, add the JDBC_QUERY_RESULT_FORMAT=JSON parameter to the Snowflake UC JDBC connection strings. For more information, refer to the updated Snowflake JDBC configuration file. |
Was this topic helpful?
Document Information
Modified date:
29 July 2026
UID
ibm17277083