Release Notes
Abstract
This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p60, resolved or known issues, security fixes, and notices associated with the patch.
Content
- Patch file name: SqlGuard-12.0p60_Bundle_Jul_09_2026.tgz.enc.sig
- MD5 checksum: b6f865008388d8bb1f8d7cdf7dd83221
Finding the patch
- Select the following options to download this patch on the IBM Fix Central website and click Continue.
- Product selector: IBM Security Guardium
- Installed Version: 12.0
- Platform: All
- On the "Identify fixes" page, select Browse for fixes and click Continue.
- On the "Select fixes" page, select Appliance Bundle. Then, enter the patch information in the Filter fix details field to locate the patch.
The latest Guardium Data Protection health check patch 12.0p9997 (see release note)
Installation
- This patch includes fixes for version 12.0.
- This patch is cumulative and includes all the fixes from previously released patches.
- This patch restarts the Guardium system.
- Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
- When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
- Download the patch and extract the compressed package outside the Guardium system.
- Review the latest version of the patch release note just before you install the patch.
- Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
- Apply the latest health check patch.
- Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
- Apply the latest universal sniffer patch.
- Apply the special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, and latest Rapid Response DPS patch.
Special Guardium Database Protection Service update (for Vulnerability Assessment only)
Guardium patch signing certificate expired on 29 March 2025
The previous patch signing certificate for Guardium appliance patches expired on 29 March 2025. Guardium appliance patches are signed by an internal certificate to validate that the patch is created by Guardium. Unsigned patch files cannot be installed. This patch is signed by the new patch signing certificate. Therefore, to install this patch, the patch signing certificate on your Guardium appliance must first be updated. For more information, see IBM Guardium - Patch signing certificate set to expire in March 2025 or contact IBM Support.
Guardium appliance bundle upgrade time extended due to MySQL tables conversion
Following MySQL support requirements, most tables are converted from MyISAM to InnoDB starting with Guardium appliance bundle versions 11.0p550 and later, and versions 12.0p25 and later. Due to the large size of some tables, which are mostly static tables, the conversion might consume more time than usual during an appliance bundle upgrade. Note: Do not cancel the patch installation process. If you have any concerns, contact IBM Support. For more information, see Guardium appliance bundle upgrade time extended due to MySQL tables conversion.
| Patch | Issue key | Summary | Known issue (APAR) |
|---|---|---|---|
| 12.0p55 | This patch includes resolved issues from 12.0p55 (see release note) | ||
| 12.0p60 | GRD-109744 | After removing ciphers with store ssl_conf command, error message appears: "The cipherlist was corrupt and has been reset to DEFAULT" | DT461729 |
| GRD-111904 | Add utilities to manage certificates monitored for distribution | DT468071 | |
| GRD-115955 | Mismatch between the DNS-resolved hostname in lowercase and the uppercase hostname set in the ADMINCONSOLE_PARAMETER, which affected the change tracker functionality | DT459423 | |
| GRD-117233 | Cannot access Guardium with IP address after SAML migration | DT462205 | |
| GRD-117559 | Incorrect OS field value for Vulnerability Assessment Test ID 798 Cassandra Default Password | DT463688 | |
| GRD-118761 | REST API remote source hostname becomes case-sensitive after upgraded from version 11.4 | DT467870 | |
| GRD-119286 | Encrypted column name in the Enterprise S-TAP report shows value 9801 for Windows S-TAP instead of the expected values of TLS or Unencrypted | DT464684 | |
| GRD-119981 | Updates duo‑universal‑sdk to version 1.3.1 to resolve authentication failures during Guardium user interface login. Only customers who use Cisco Duo MFA for authentication are affected. For more information, see Guardium GUI Login Failure with Duo MFA. | ||
| GRD-121826 | SNMP alerter service stops unexpectedly preventing trap delivery | DT467797 | |
| GRD-121950 | Backport MongoDB Vulnerability Assessment Test ID 897 | DT474738 | |
| GRD-122334 | AWS Kinesis stream discovery fails with IAM instance profile authentication | ||
| GRD-122755 | Real-time Trust Evaluator displays decommissioned collectors instead of active ones | DT473919 | |
| GRD-123236 | Remove proxy settings from Qualys VM scanner configuration | DT468930 | |
| GRD-123672 | False positive results from Vulnerability Assessment scans for Microsoft SQL Server CVE tests | DT469687 | |
| GRD-123786 | Multiple managed units show intermittent "unit not responding" in Deployment Health table | DT473163 | |
| GRD-128574 | Resolve GIM server support for new 12.x versioning convention for single-stream agent release packages. Only customers who use GIM to install and manage agents are affected. For more information, see Single-stream agent releases. |
| Patch | Issue key | Summary | CVE |
|---|---|---|---|
| 12.0p55 | This patch includes security fixes from 12.0p55 (see release note) | ||
| 12.0p60 | GRD-102088 | PSIRT: PVR0668193 - commons-beanutils-1.9.2.jar (Publicly disclosed vulnerability found by Mend) - IBM Spectrum Protect (Tivoli Storage Manager) | CVE-2025-48734 |
| GRD-116334 | PSIRT: PVR0694349 - lz4-1.3.0.jar (Publicly disclosed vulnerability found by Scanner) - Datastreams | CVE-2025-66566 | |
| GRD-117726 | PSIRT : PVR0697335 log4j-core-2.17.1.jar (Publicly disclosed vulnerability found by Scanner) - Cruise control | CVE-2025-68161 | |
| GRD-119114 | PSIRT : PVR0707166 protobuf-3.18.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Publicly disclosed vulnerability found by Scanner) | CVE-2026-0994 | |
| GRD-119194 | PSIRT : PVR0707575 IBM Java (Publicly disclosed vulnerability found by Scanner) | CVE-2026-21945, CVE-2026-21932, CVE-2026-21933, CVE-2026-21925 | |
| GRD-119200 | PSIRT : PVR0710436 IBM Java (Publicly disclosed vulnerability found by Scanner) | CVE-2026-1188 | |
| GRD-119470 | PSIRT: PVR0667170 - http2-common-10.0.22.jar (Publicly disclosed vulnerability found by Mend) - SOLR | CVE-2025-5115 | |
| GRD-124470 | PSIRT: PVR0754821 - IBM SDK, Java Technology Edition Quarterly CPU - April 2026 - Includes Oracle April 2026 CPU | CVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007 | |
| GRD-124978 | PSIRT: PVR0761523 - postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-42198 | |
| GRD-124981 | PSIRT - PVR0760981, PVR0763120 : libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner) | CVE-2026-41603, CVE-2026-43869 |
| Issue key | Summary |
|---|---|
| GRD-130103 | Running the store alerter snmp traphost command does not set the Alerter SNMP trap server to receive alerts as expected. Workaround: Use the GUI to set the Alerter SNMP trap server. Go to go to Setup > Tools and Views > Alerter and follow the Configure the alerter to use SNMP procedure in product documentation. |
Was this topic helpful?
Document Information
Modified date:
21 July 2026
UID
ibm17279452