IBM Support

Release of Special Guardium Database Protection Service update for Guardium 12.2.3, 12.0p60, and 12.0p145

Release Notes


Abstract

This document is intended for Guardium Vulnerablity Assessment 12.x clients who upgrade to Guardium Data Protection versions 12.2.3 (GPU 12.0p230), 12.0p60, or 12.0p145. It lists the updates that are available for Guardium Database Protection Service (DPS), a subscription service that provides periodic updates to vulnerability tests as well as other predefined content, including reports, groups, and policies.

Content

Target audience

This document is intended for Guardium Vulnerablity Assessment 12.x clients who upgrade to Guardium Data Protection 12.2.3 (GPU 12.0p230), or appliance patches 12.0p60 or 12.0p145. The Guardium 12.x Special DPS file described in this document must be applied after you upgrade to those 12.x versions from a previous version. 

Customers should also check IBM Support Fix Central for the latest Rapid Response DPS release and apply it after uploading this special DPS file.
 

Attention

If this Special DPS update is not applied, customers might see some false positive results from their Vulnerability Assessment scans for Microsoft SQL Server CVE tests.

 
 
DPS file
Fix IDGuardium_12.X_DPS-Special-Q2-2026
File nameGuardium_V12_Quarterly_DPS_2026_Q2_20260617.enc
MD5SUMad382282a45ab9f93848c8a9a41f37c0
 
 
Prerequisites
Guardium Data Protection patch 12.2.3 (see release note), 12.0p60 (see release note), or 12.0p145 (see release note)

 
Enhancements
This file includes the following enhancements.
Issue keySummary
GRD-120727Assessment Tests for EDB PostgreSQL based on the latest CIS PostgreSQL 17 benchmarks
GRD-121775
Data source currency updates for Couchbase 7.6, 8.0
GRD-121801Data source currency updates for DataStax Cassandra 6.8
GRD-121768
Data source currency updates for Oracle 26ai (includes on-prem and autonomous cloud)
 
 
Vulnerability Assessment test enhancements
 

New query-based tests

Test IDDescription
4425Ensure the log file destination directory is set correctly - EDB
4426Ensure log_timezone is set correctly. - EDB
4427Ensure backend runtime parameters are configured correctly - EDB
4428Ensure logging of replication commands is configured - EDB
4429Ensure log_error_verbosity is set correctly - EDB
4430Ensure syslog messages are not lost due to size - EDB
4431Ensure syslog messages are not suppressed - EDB
4432Ensure that TLSv1.3, or later, is configured - EDB
 

Updated query-based tests 

Test IDDescription
4133Ensure excessive function privileges are revoked - EDB
4137Ensure log_line_prefix is set correctly - EDB
4140Ensure TLS is enabled - EDB
4152Ensure WAL archiving is configured and functional - EDB
4173The EDB Postgres Advanced Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts.

 

Updated CVE tests
 
Test IDTest name
8028CVE-2015-1761
8029CVE-2015-1762
8030CVE-2015-1763
8635CVE-2017-5715
8636CVE-2017-5753
8637CVE-2017-5754
8876CVE-2020-0618
9043CVE-2021-1636
9526CVE-2023-21528
9527CVE-2023-21704
9528CVE-2023-21705
9529CVE-2023-21713
9530CVE-2023-21718
9536CVE-2023-23384
9942CVE-2026-20803
 
 
New groups
Group IDDescription
462MarkLogic system roles
463PHI Databases
465HITRUST Server IPs
466HITRUST Server IPs - Hierarchical
467HITRUST Authorized Applications
468HITRUST Authorized Users
469HITRUST Privileged Users
470HITRUST Authorized Client IPs
471HIPAA PHI Databases
472HIPAA PHI Objects
473HIPAA PHI Server IPs
474HIPAA PHI Server IPs - Hierarchical
475HIPAA Authorized Healthcare Applications
476HIPAA Authorized Client IPs
477HIPAA Authorized Users
478HIPAA Admin Users
479LGPD Personal Data Authorized Client IPs
480LGPD Personal Data DBs
481LGPD Personal Data Sensitive Objects
482LGPD Personal Data Authorized Server IPs
483LGPD Personal Data Authorized Server IPs - Hierarchical
484LGPD Personal Data Authorized Source Programs
485LGPD Personal Data Admin Users
486LGPD Personal Data Authorized Users
487PDPA Personal Data Databases
488PDPA Personal Data Sensitive Objects
489PDPA Personal Data Server IPs
490PDPA Authorized Applications
491PDPA Authorized Users
492PDPA Server IPs
493PDPA Server IPs - Hierarchical
494PIPEDA Personal Information Databases
495PIPEDA Personal Information Server IPs
496PIPEDA Personal Information Server IPs - Hierarchical
497PIPEDA Authorized Applications
498PIPEDA Authorized Users
499POPIA Personal Information Databases
500POPIA Personal Data Sensitive Objects
501POPIA Personal Information Server IPs
502POPIA Personal Information Server IPs - Hierarchical
503POPIA Authorized Applications
504POPIA Authorized Users
505PDPA Admin Users
507PIPEDA Personal Data Sensitive Objects
508PIPEDA Admin Users
509POPIA Admin Users
510HITRUST -  Sensitive Data Authorized Admin Users
511HITRUST -  Sensitive Object
512HITRUST Admin Users
513Privileged Database Grant Patterns
514Authentication Failed Error Codes
515DB Unavailability Error Codes
 
 
Resolved issues
 
Issue keySummaryAPAR
GRD-123672Fixed false positives that occurred in Vulnerability Assessment tests with some Microsoft SQL Server CVE tests.DT469687
 
 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m0z000000cvkbAAA","label":"DPS"},{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.0.0;12.1.0;12.2.0"}]

Document Information

Modified date:
21 July 2026

UID

ibm17278751