IBM Support

Release of Guardium Data Protection patch 12.0p231

Release Notes


Abstract

This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p231, including resolved or known issues, or notices associated with the patch.

Content

Patch information
  • Patch file name: SqlGuard-12.0p231.tgz.enc.sig
  • MD5 checksum: afcb6912901e6c88d2ba789f7112c323
 

Finding the patch

  1. Select the following options to download this patch on the IBM Fix Central website and click Continue.
    • Product selector: IBM Security Guardium
    • Installed Version: 12.2
    • Platform: All
  2. On the "Identify fixes" page, select Browse for fixes and click Continue.
  3. On the "Select fixes" page, select Other Patch. Then, enter the patch information in the Filter fix details field to locate the patch.
 
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
 
 
Prerequisites
  • Guardium Data Protection 12.0p230 (see release note)
  • The latest Guardium Data Protection health check patch 12.0p9997 (see release note)
 
 

Installation

Notes:
  • This patch restarts the Guardium system.
  • Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
  • When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
 
Overview:
  1. Download the patch and extract the compressed package outside the Guardium system.
  2. Review the latest version of the patch release notes just before you install the patch.
  3. Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
  4. Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
 
For information about installing Guardium Data protection patches, see Installing patches in the Guardium documentation.

 

 
Resolved issues 
PatchIssue keySummaryKnown issue (APAR)
    
12.0p231GRD-129441Guardium 12.2.1 appliance with Neo4J datasource (SSL enabled) failed to connect after upgrading to Guardium 12.2.2. DT496673
 GRD-130574After installing GPU 12.0p230 on a Guardium version 12.2.x appliance, lightweight directory access protocol (LDAP) authentication might fail. The fix prevents GPU installation from corrupting or overwriting the LDAP truststore and preserves existing LDAP certificate trust relationships. For more information, see LDAP Authentication Failure After GPU P230 InstallationDT495636
 GRD-130614Fixed allocation issue during bulk reinstall of universal connector profiles in an environment with different collectors. 
 

 

Security fixes 
PatchIssue keySummaryCVE
12.0p231GRD-122446PSIRT: PVR0730977 : jackson-core-2.16.2.jar (Publicly disclosed vulnerability found by Scanner)WS-2026-0003
 GRD-128704PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : samba (RHSA-2026:25049)CVE-2026-1933, CVE-2026-2340, CVE-2026-3012, CVE-2026-40170, CVE-2026-4408, CVE-2026-4480
 GRD-128939PSIRT : PVR0784611 - micrometer-core-1.14.2.jar (Publicly disclosed vulnerability found by mend Scanner)CVE-2026-40984
 GRD-129146PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : rsync (RHSA-2026:26410) CVE-2026-29518, CVE-2026-43618
 GRD-129147PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : podman (RHSA-2026:26447)CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,CVE-2026-25679, CVE-2026-25681, CVE-2026-27136, CVE-2026-39829, CVE-2026-39832, CVE-2026-39835, CVE-2026-42508, CVE-2026-57231, CVE-2026-39822
 GRD-129370PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : python-cryptography (RHSA-2025:15874)CVE-2023-49083
 GRD-129375PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : openssl (RHSA-2026:25239)CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-7383, CVE-2026-9076
 GRD-129377PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : openssl-fips-provider (RHSA-2026:27744)CVE-2026-31790
 GRD-129378PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : kernel (RHSA-2026:27708)CVE-2025-40064, CVE-2025-40168 CVE-2026-43116, CVE-2026-43158, CVE-2026-43303, CVE-2026-45898, CVE-2026-46125, CVE-2026-46166, CVE-2026-46243, CVE-2026-46323, CVE-2026-46331, CVE-2026-31411, CVE-2026-43198, CVE-2026-31488, CVE-2026-43038, CVE-2026-43329, CVE-2026-45898, CVE-2026-46054, CVE-2026-46090, CVE-2026-46176, CVE-2026-46189, CVE-2026-31474, CVE-2026-31669, CVE-2026-31772, CVE-2026-31787, CVE-2026-43260, CVE-2026-43279, CVE-2026-43414, CVE-2026-45984, CVE-2026-46056, CVE-2026-46117, CVE-2026-46125, CVE-2026-46135, CVE-2026-46145, CVE-2026-46152, CVE-2026-46166, CVE-2026-46173, CVE-2026-46331, CVE-2025-10263, CVE-2026-43112, CVE-2026-43276, CVE-2026-46116, CVE-2026-46155, CVE-2026-46209, CVE-2026-46227, CVE-2026-46244, CVE-2026-46259, CVE-2026-46316, CVE-2026-46323, CVE-2025-71066, CVE-2026-46113, CVE-2026-53359, CVE-2026-43074, CVE-2026-46242, CVE-2026-53266, CVE-2026-22979, CVE-2026-43499, CVE-2026-46086, CVE-2026-53016
 GRD-129585PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : libpng (RHSA-2026:28255) CVE-2026-33416, CVE-2026-33636
 GRD-129588PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : libxml2 (RHSA-2026:28254)CVE-2024-34459, CVE-2025-6170
 GRD-129674PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : runc (RHSA-2026:29702)CVE-2026-25679, CVE-2026-32280, CVE-2026-32281
 GRD-129677PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : gnutls (RHSA-2026:30004)CVE-2026-33845, CVE-2026-33846, CVE-2026-3833, CVE-2026-42009, CVE-2026-42010, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015, CVE-2026-5260, CVE-2026-5419
 GRD-129909PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : perl-Archive-Tar (RHSA-2026:30856)CVE-2026-42496
 GRD-129910PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : perl-IO-Compress (RHSA-2026:30859)CVE-2026-48962
 GRD-129982PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : glibc (RHSA-2026:33226)CVE-2026-5450
 GRD-130091PSIRT : PVR0825708 - SE - Qualys - Apache Tomcat security updateCVE-2026-24880, CVE-2026-25854, CVE-2026-29145, CVE-2026-29146, CVE-2026-32990, CVE-2026-34483, CVE-2026-34487, CVE-2026-34500, CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43512, CVE-2026-43513, CVE-2026-43514, CVE-2026-43515
 GRD-130595PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : freeipmi (RHSA-2026:36210)CVE-2026-50031
 GRD-130597PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : aardvark-dns (RHSA-2026:36318)CVE-2026-35406
 GRD-130664PSIRT : PVR0825708 - SE - Nessus - RHEL 9 : buildah (RHSA-2026:37410)CVE-2026-39832, CVE-2026-39835, CVE-2026-39822, CVE-2026-39830, CVE-2026-32281, CVE-2026-39829
 
 
Known limitations and workarounds 
PatchIssue keySummary
12.0p231GRD-133413

After installing patch 12.0p231, systems using EFI as the bootloader might get stuck at the GRUB prompt during the boot process and not proceed to load the operating system.

Workaround: Use the following command on the GRUB menu to bring back the system: configfile (hd0,gpt2)/grub2/grub.cfg 

[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDKGA","label":"IBM Guardium Data Protection"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.2.3"}]

Document Information

Modified date:
14 September 2026

UID

ibm17282708