IBM Support

Release of Guardium Data Protection Windows S-TAP 12.xp100 r120203321

Release Notes


Abstract

This technical note provides guidance for installing IBM Guardium Data Protection Windows Agents 12.xp100 r120203321, including any new features or enhancements, resolved or known issues, or notices associated with the patch.

Content

Patch information
Product:IBM Guardium
Release version:Guardium 12.xp100 Windows Software TAP (S-TAP)
Completion date:9 July 2026
 
 
Fix IDs
Guardium_12.x.p100_r120203321_S-TAP_Windows
 
 
Finding the patch
  1. Select the following options to download this patch on the IBM Fix Central website and click Continue.
    • Product selector: IBM Security Guardium
    • Installed Version: 12.0, 12.1, 12.2, or 12.x
    • Platform: Windows
  2. On the "Identify fixes" page, select Browse for fixes and click Continue.
  3. On the "Select fixes" page, select Database Agent (STAP, GIM and CAS). Then, enter the patch information in the Filter fix details field to locate the patch.
 
Notes
  • A fresh install of Guardium Windows S-TAP 12.x does not require a reboot.
  • When you upgrade between versions, you must reboot the database server to update the NmpProxy driver. If there are no issues with your current NmpProxy functionality, you can delay the reboot until the next maintenance cycle. No fixes will be applied to the NmpProxy driver until a server reboot is completed.
 
Attention
 

Single-stream agent releases 
Most of the Linux-UNIX and Windows agents for Guardium Data Protection versions 12.0 and later are now released as single stream, cumulative updates. File names starting with "12.x" are now applicable to all current (12.0, 12.1, and 12.2) and future minor version releases within the Guardium 12.x family. The new naming convention follows a sequence, such as 12.xp100, 12.xp101, and so on. 

To accommodate the single-stream packaging change, ad-hoc appliance patches are required for any GIM-managed Linux-UNIX or Windows Agents customer environment before upgrading to the new single-stream agent release packages.  Visit Single-stream agent releases to identify the ad-hoc patch that aligns with your specific Guardium appliance version, and follow the prescribed upgrade sequence. 

Important: Do not upload Linux-UNIX Agents 12.xp101 or later, or Windows Agents 12.x.p100 or later to a GIM server that does not yet have this appliance patch installed because the bundle will not process correctly.

Note: Customers who already upgraded to Guardium 12.2.3 (GPU 12.0p230, see release note) or do not use GIM to install and manage agents do not need to apply these ad-hoc patches to use the new single-stream agent release packages.

 
 
New features and enhancements
 
Model Context Protocol support
Support added for the Guardium Model Context Protocol (MCP) server, enabling standardized access to Guardium capabilities for AI agents and removing the need for feature-specific integration code. 
 
A new AUTO_DISCOVERY_EXCLUDED_DBTYPES installation parameter accepts a comma-separated list of database types, whose inspection engines will be preserved when Auto-Discovery runs, rather than being overwritten. Discovered instances for excluded types are still reported to the appliance, ensuring visibility is maintained while preventing Auto-Discovery from removing inspection engines it cannot recreate, such as MCP.
 
 
Resolved issues
Patch
Issue keySummaryKnown issue (APAR)
12.2.2.259 
See release notes for Windows S-TAP 12.2.2.259
 
12.xp100 r120203321GRD-115230, 
GRD-118269, 
GRD-118720, 
GRD-120333, 
GRD-120572, 
GRD-122380
Fixed an issue in WfpMonitor that might lead to an instability in the database server. For more information, see Windows S-TAP 12.2.x, 12.1.x, 12.0.x, and 11.5.x can cause unexpected MSSQL server termination when partial or malformed TDS PDUs are processed.DT457509
 GRD-117204Fixed an S-TAP instability following an upgrade with protocol 7 by clearing leftover registry entries.DT460464
 GRD-117571Improved S-TAP robustness to avoid S-TAP instability even when memory resources are critically low.DT465036
 GRD-120066, 
GRD-120804
Fixed S-GATE Terminate functionality to properly process verdicts when multiple threads are handling firewall decisions concurrently.DT464028
 GRD-120622Fixed an issue where Windows FAM incorrectly reported a local adapter IP address as the Client IP instead of the server IP address during Remote Desktop sessions. For some RDP client software (such as Microsoft Windows App for Mac) where the actual remote client IP cannot be obtained, FamMonitor now correctly uses the server IP for both Client IP and Server IP fields instead of showing an incorrect local adapter address.DT468851
 GRD-120832Increased maximum value for LOAD_BALANCER_NUM_MUS to 300 and the buffer size to 64 KB.DT465008
 GRD-125132The Auto-Discovery logic is updated to correctly enumerate ports from per-IP registry keys when ListenOnAllIPs=0, ensuring inspection engines are created for all actively listening Microsoft SQL Server ports.DT474476
 GRD-120773OpenSSL is updated to version 3.5.5 to and the installer now removes all residual OpenSSL binaries from installation directories during upgrade.DT468509
 GRD-123835The Windows GIM and S-TAP installers now target .NET Framework 4.6 instead of 4.5, aligning with Windows Server 2016 and later default framework versions. Improved logging messages are added for .NET detection failures to aid troubleshooting.DT474424
 GRD-126326Fixed Windows S-TAP installer to remove old WFP driver configurations before installing or upgrading, preventing network connectivity loss caused by incompatible version 11.5 configurations being used with version 12.2 and later drivers.DT474430
 GRD-126569Enhanced the Windows Must Gather diagnostic script to collect comprehensive .NET Framework registry information for troubleshooting .NET Framework-related issues. 
 
 
Known issues and workarounds
Issue keyDescription

GRD-120061 

If an Oracle table is built with NVARCHAR2 columns, running a predefined REDACT rule action (fast scrub) does not mask credit card details. 

Workaround: Use a regular expression (regex) to set up a scrub action. For guidance, see REDACT - Working with regex on Windows DB servers.  

GRD-122049 

When Windows S-TAP is configured with UPLOAD_FEATURE=1 and a debug snapshot is triggered from a managed unit, the diagnostic .zip file is uploaded only to the collector and not to the central manager.

Workaround: Restart the sniffer service after registering collector to the central manager.

 

 

Installers with MD5Sums
MD5SumFile Name
90a25bc4bc620c2c3e82862162866a69Windows-STAP-12.x.p100_r120203321.zip
381ede1021db5100f82a31e1b0e3430econf.reload.WINSTAP
6f1a634baeb6a33cb3e38d6940df03cdguard-WINSTAP-12.x.p100_r120203321_1-x86_x64.gim
646a56af37e8ed64321a34a93dc0c364guard-WINSTAP-guardium_12.x.p100_r120203321_1-Windows-Server-Windows-x86_x64.exe.signed
 
 
Related Guardium updates
  • Guardium Data Protection 12.2.3 (GPU 12.0p230, see release note)
  • Guardium Data Protection Windows CAS 12.xp100 r120203321 (see release note)
  • Guardium Data Protection Windows FamMonitor 12.xp100 r120203321 (see release note)
  • Guardium Data Protection Windows GIM 12.xp100 r120203321 (see release note)
 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"},{"code":"a8m0z000000Gp0IAAS","label":"STAP"}],"ARM Case Number":"","Platform":[{"code":"PF033","label":"Windows"}],"Version":"12.0.0;12.1.0;12.2.0"}]

Document Information

Modified date:
09 July 2026

UID

ibm17278217