IBM Support

Release of Guardium Data Protection patch 12.0p60

Release Notes


Abstract

This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p60, resolved or known issues, security fixes, and notices associated with the patch.

Content

Patch information
  • Patch file name: SqlGuard-12.0p60_Bundle_Jul_09_2026.tgz.enc.sig
  • MD5 checksum: b6f865008388d8bb1f8d7cdf7dd83221
 

Finding the patch

  1. Select the following options to download this patch on the IBM Fix Central website and click Continue.
    • Product selector: IBM Security Guardium
    • Installed Version: 12.0
    • Platform: All
  2. On the "Identify fixes" page, select Browse for fixes and click Continue.
  3. On the "Select fixes" page, select Appliance Bundle. Then, enter the patch information in the Filter fix details field to locate the patch.
 
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
 
 
Prerequisites

The latest Guardium Data Protection health check patch 12.0p9997 (see release note)

 
 

Installation

Notes:
  • This patch includes fixes for version 12.0.
  • This patch is cumulative and includes all the fixes from previously released patches.
  • This patch restarts the Guardium system.
  • Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
  • When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
 
Overview:
  1. Download the patch and extract the compressed package outside the Guardium system.
  2. Review the latest version of the patch release note just before you install the patch.
  3. Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
  4. Apply the latest health check patch.
  5. Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
  6. Apply the latest universal sniffer patch.
  7. Apply the special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, and latest Rapid Response DPS patch.
 
For information about installing Guardium Data protection patches, see How to install patches in the Guardium documentation.
 
 
Attention

Special Guardium Database Protection Service update (for Vulnerability Assessment only) 
A special Guardium Database Protection Service (DPS) update, Guardium_12.X_DPS-Special-Q2-2026, which is available for download from Fix Central, must be applied after you upgrade to Guardium 12.p60 from previous versions. See release notes for detailed file information. 
 
If the Special DPS update is not applied, customers might see some false positive results from their Vulnerability Assessment scans for Microsoft SQL Server CVE tests. 
 
Be sure to also check Fix Central for the latest Rapid Response DPS release and apply it after uploading the Special DPS file.
 

Guardium patch signing certificate expired on 29 March 2025
The previous patch signing certificate for Guardium appliance patches expired on 29 March 2025. Guardium appliance patches are signed by an internal certificate to validate that the patch is created by Guardium. Unsigned patch files cannot be installed. This patch is signed by the new patch signing certificate. Therefore, to install this patch, the patch signing certificate on your Guardium appliance must first be updated. For more information, see IBM Guardium - Patch signing certificate set to expire in March 2025 or contact IBM Support.

Guardium appliance bundle upgrade time extended due to MySQL tables conversion       
Following MySQL support requirements, most tables are converted from MyISAM to InnoDB starting with Guardium appliance bundle versions 11.0p550 and later, and versions 12.0p25 and later. Due to the large size of some tables, which are mostly static tables, the conversion might consume more time than usual during an appliance bundle upgrade. Note: Do not cancel the patch installation process. If you have any concerns, contact IBM Support. For more information, see Guardium appliance bundle upgrade time extended due to MySQL tables conversion

 

Resolved issues
PatchIssue keySummaryKnown issue (APAR)
12.0p55 This patch includes resolved issues from 12.0p55 (see release note) 
12.0p60GRD-109744After removing ciphers with store ssl_conf command, error message appears: "The cipherlist was corrupt and has been reset to DEFAULT"DT461729
 GRD-111904Add utilities to manage certificates monitored for distributionDT468071
 GRD-115955Mismatch between the DNS-resolved hostname in lowercase and the uppercase hostname set in the ADMINCONSOLE_PARAMETER, which affected the change tracker functionalityDT459423
 GRD-117233Cannot access Guardium with IP address after SAML migrationDT462205
 GRD-117559Incorrect OS field value for Vulnerability Assessment Test ID 798 Cassandra Default PasswordDT463688
 GRD-118761REST API remote source hostname becomes case-sensitive after upgraded from version 11.4DT467870
 GRD-119286Encrypted column name in the Enterprise S-TAP report shows value 9801 for Windows S-TAP instead of the expected values of TLS or UnencryptedDT464684
 GRD-119981Updates duo‑universal‑sdk to version 1.3.1 to resolve authentication failures during Guardium user interface login. Only customers who use Cisco Duo MFA for authentication are affected. For more information, see Guardium GUI Login Failure with Duo MFA. 
 GRD-121826SNMP alerter service stops unexpectedly preventing trap deliveryDT467797
 GRD-121950Backport MongoDB Vulnerability Assessment Test ID 897DT474738
 GRD-122334AWS Kinesis stream discovery fails with IAM instance profile authentication 
 GRD-122755Real-time Trust Evaluator displays decommissioned collectors instead of active onesDT473919
 GRD-123236Remove proxy settings from Qualys VM scanner configurationDT468930
 GRD-123672False positive results from Vulnerability Assessment scans for Microsoft SQL Server CVE testsDT469687
 GRD-123786Multiple managed units show intermittent "unit not responding" in Deployment Health tableDT473163
 GRD-128574Resolve GIM server support for new 12.x versioning convention for single-stream agent release packages. Only customers who use GIM to install and manage agents are affected. For more information, see Single-stream agent releases. 

 
Security fixes
PatchIssue keySummaryCVE
12.0p55 This patch includes security fixes from 12.0p55 (see release note) 
12.0p60GRD-102088PSIRT: PVR0668193 - commons-beanutils-1.9.2.jar (Publicly disclosed vulnerability found by Mend) - IBM Spectrum Protect (Tivoli Storage Manager)CVE-2025-48734
 GRD-116334PSIRT: PVR0694349 - lz4-1.3.0.jar (Publicly disclosed vulnerability found by Scanner) - Datastreams
CVE-2025-66566
 GRD-117726PSIRT : PVR0697335 log4j-core-2.17.1.jar (Publicly disclosed vulnerability found by Scanner) - Cruise controlCVE-2025-68161
 GRD-119114PSIRT : PVR0707166 protobuf-3.18.3-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Publicly disclosed vulnerability found by Scanner)CVE-2026-0994
 GRD-119194PSIRT : PVR0707575 IBM Java (Publicly disclosed vulnerability found by Scanner)CVE-2026-21945, CVE-2026-21932, CVE-2026-21933, CVE-2026-21925
 GRD-119200PSIRT : PVR0710436 IBM Java (Publicly disclosed vulnerability found by Scanner)CVE-2026-1188
 GRD-119470PSIRT: PVR0667170 - http2-common-10.0.22.jar (Publicly disclosed vulnerability found by Mend) - SOLRCVE-2025-5115
 GRD-124470PSIRT: PVR0754821 - IBM SDK, Java Technology Edition Quarterly CPU - April 2026 - Includes Oracle April 2026 CPUCVE-2026-22016, CVE-2026-22021, CVE-2026-22013, CVE-2026-22018, CVE-2026-34268, CVE-2026-22007
 GRD-124978PSIRT: PVR0761523 - postgresql-42.5.6.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-42198
 GRD-124981PSIRT - PVR0760981, PVR0763120 : libthrift-0.10.0.jar (Publicly disclosed vulnerability found by MEND Scanner)CVE-2026-41603, CVE-2026-43869
 
 
Known limitations and workarounds
Issue keySummary
GRD-130103

Running the store alerter snmp traphost command does not set the Alerter SNMP trap server to receive alerts as expected. 

Workaround: Use the GUI to set the Alerter SNMP trap server. Go to go to Setup > Tools and Views > Alerter and follow the Configure the alerter to use SNMP procedure in product documentation.

 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.0.0"}]

Document Information

Modified date:
21 July 2026

UID

ibm17279452