Release Notes
Abstract
This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p233, including resolved or known issues, or notices associated with the patch.
Content
Patch information
- Patch file name: SqlGuard-12.0p233.tgz.enc.sig
- MD5 checksum: 57bb81f6c68172b2c8036af4771ee360
Finding the patch
- Select the following options to download this patch on the IBM Fix Central website and click Continue.
- Product selector: IBM Security Guardium
- Installed Version: 12.2
- Platform: All
- On the "Identify fixes" page, select Browse for fixes and click Continue.
- On the "Select fixes" page, select Other Patch. Then, enter the patch information in the Filter fix details field to locate the patch.
For information about Guardium patch types and naming conventions, see the Understanding Guardium patch types and patch names support document.
Prerequisites
- Guardium Data Protection 12.0p230 (see release notes)
- The latest Guardium Data Protection health check patch 12.0p9997 (see release notes)
Installation
Notes:
- This patch restarts the Guardium system.
- Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
- When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
Overview:
- Download the patch and extract the compressed package outside the Guardium system.
- Review the latest version of the patch release notes just before you install the patch.
- Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
- Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
For information about installing Guardium Data Protection patches, see Installing patches in the Guardium documentation.
Resolved issues
| Patch | Issue key | Summary | Known issue (APAR) |
|---|---|---|---|
| 12.0p232 | This patch includes resolved issues from 12.0p232 (see release notes) | ||
| 12.0p233 | GRD-127653 | S-TAP clusters missing from S-TAP by cluster view of Deployment Health Table | DT498551 |
| GRD-128297 | Classification scan halts after 30-minute timeout | DT498134 | |
| GRD-129819 | Kafka rebalancing creates multiple sessions | ||
| GRD-130000 | Active threat analytics case details restricted to admin role only | DT498118 | |
| GRD-130119 | Server IP aliases defined in alias builder not displayed in S-TAP Control page | DT499099 | |
| GRD-132728 GRD-133106 | SNMP traffic blocked after firewall rule change that migrated iptables to nftables | DT498574 DT498574 | |
| GRD-132803 | Added fix to prevent faulty Windows Guardium Installation Manager (GIM) clients from causing disruption with the GIM server after upgrade. | DT499183 | |
| GRD-133477 | Active threat analytics cases and custom categories missing after upgrade | DT499578 |
Security fixes
| Patch | Issue key | Summary | CVE |
|---|---|---|---|
| 12.0p233 | GRD-129212 | PSIRT: PVR0787223, PVR0788318, PVR0789744 - netty-handler-4.1.133.Final.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-44249, CVE-2026-45416, CVE-2026-50010 |
| GRD-129916 | PSIRT: PVR0801016, PVR0801168, PVR0820258, PVR0820328, PVR0842146 - jackson-databind-2.19.2.jar (Publicly disclosed vulnerability found by mend Scanner) | CVE-2026-18401, CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515, CVE-2026-54516, CVE-2026-54517, CVE-2026-54518, CVE-2026-59888, CVE-2026-59889, CVE-2026-68494 | |
| GRD-130089 | PSIRT: PVR0871011 - SE - Qualys - Oracle MySQL security update | CVE-2026-21998, CVE-2026-22001, CVE-2026-22002, CVE-2026-22004, CVE-2026-22005, CVE-2026-22009, CVE-2026-22015, CVE-2026-22017, CVE-2026-34267, CVE-2026-34270, CVE-2026-34271, CVE-2026-34272, CVE-2026-34276, CVE-2026-34278, CVE-2026-34293, CVE-2026-34303, CVE-2026-34304, CVE-2026-34308, CVE-2026-35234, CVE-2026-35235, CVE-2026-35236, CVE-2026-35237, CVE-2026-35238, CVE-2026-35239, CVE-2026-35240 | |
| GRD-131695 | PSIRT: PVR0834802 - [GDP-g004] Command injection | ||
| GRD-131696 | PSIRT: PVR0834803 - [GDP-g005] SQL injection | ||
| GRD-131697 | PSIRT: PVR0834804 - [GDP-g006] OS command injection | ||
| GRD-131698 | PSIRT: PVR0834805 - [GDP-g007] SQL injection | ||
| GRD-131699 | PSIRT: PVR0834806 - [GDP-g008] SQL injection | ||
| GRD-131700 | PSIRT: PVR0834807 - [GDP-g009] Missing authentication | ||
| GRD-131702 | PSIRT: PVR0834809 - [GDP-g011] SQL injection | ||
| GRD-131703 | PSIRT: PVR0834810 - [GDP-g012] Hard-coded key and credentials | ||
| GRD-131704 | PSIRT: PVR0834811 - [GDP-g013] SQL injection | ||
| GRD-131705 | PSIRT: PVR0834812 - [GDP-g014] Unsafe deserialization | ||
| GRD-131706 | PSIRT: PVR0834813 - [GDP-g015] SQL injection | ||
| GRD-131709 | PSIRT: PVR0834816 - [GDP-g018] SQL injection | ||
| GRD-131710 | PSIRT: PVR0834817 - [GDP-g019] Command injection | ||
| GRD-131711 | PSIRT: PVR0834818 - [GDP-g020] Command injection | ||
| GRD-131713 | PSIRT: PVR0834820 - [GDP-g022] Command injection | ||
| GRD-131714 | PSIRT: PVR0834821 - [GDP-g023] Command injection | ||
| GRD-131715 | PSIRT: PVR0834822 - [GDP-g024] Command injection | ||
| GRD-131717 | PSIRT: PVR0834824 - [GDP-g026] Code/template injection | ||
| GRD-131720 | PSIRT: PVR0834827 - [GDP-g029] OS command injection | ||
| GRD-131726 | PSIRT: PVR0834833 - [GDP-g035] Missing authentication | ||
| GRD-131736 | PSIRT: PVR0834843 - [GDP-g045] Hard-coded/default credentials | ||
| GRD-131738 | PSIRT: PVR0834845 - [GDP-g047] Race condition | ||
| GRD-131739 | PSIRT: PVR0834846 - [GDP-g048] Cross-site scripting | ||
| GRD-131741 | PSIRT: PVR0834848 - [GDP-g050] Cross-site scripting | ||
| GRD-131742 | PSIRT: PVR0834849 - [GDP-g051] Cross-site scripting | ||
| GRD-131743 | PSIRT: PVR0834850 - [GDP-g052] Cross-site scripting | ||
| GRD-131744 | PSIRT: PVR0834851 - [GDP-g053] Command injection | ||
| GRD-131745 | PSIRT: PVR0834852 - [GDP-g054] Authentication bypass | ||
| GRD-131746 | PSIRT: PVR0834853 - [GDP-g055] SQL injection | ||
| GRD-131747 | PSIRT: PVR0834854 - [GDP-g056] Cross-site request forgery | ||
| GRD-131751 | PSIRT: PVR0834858 - [GDP-g060] Missing/broken authentication | ||
| GRD-131753 | PSIRT: PVR0834860 - [GDP-g062] OS command injection | ||
| GRD-131754 | PSIRT: PVR0834861 - [GDP-g063] Path traversal/arbitrary file access | ||
| GRD-131756 | PSIRT: PVR0834863 - [GDP-g065] OS command injection | ||
| GRD-131758 | PSIRT: PVR0834865 - [GDP-g067] Cross-site request forgery | ||
| GRD-131760 | PSIRT: PVR0834867 - [GDP-g069] Path traversal/arbitrary file access | ||
| GRD-131761 | PSIRT: PVR0834868 - [GDP-g070] Improper certificate validation | ||
| GRD-131763 | PSIRT: PVR0834870 - [GDP-g072] Cross-site scripting | ||
| GRD-131764 | PSIRT: PVR0834871 - [GDP-g073] Local privilege escalation (SUID) | ||
| GRD-131765 | PSIRT: PVR0834872 - [GDP-g074] Local privilege escalation (SUID) | ||
| GRD-131766 | PSIRT: PVR0834873 - [GDP-g075] Local privilege escalation (SUID) | ||
| GRD-131767 | PSIRT: PVR0834874 - [GDP-g076] Local privilege escalation (SUID) | ||
| GRD-131769 | PSIRT: PVR0834876 - [GDP-g078] SQL injection | ||
| GRD-131770 | PSIRT: PVR0834877 - [GDP-g079] Authorization bypass | ||
| GRD-131771 | PSIRT: PVR0834878 - [GDP-g080] SQL injection | ||
| GRD-131772 | PSIRT: PVR0834879 - [GDP-g081] Path traversal | ||
| GRD-131773 | PSIRT: PVR0834880 - [GDP-g082] Hard-coded/default credentials | ||
| GRD-131774 | PSIRT: PVR0834881 - [GDP-g083] Authorization bypass | ||
| GRD-131775 | PSIRT: PVR0834882 - [GDP-g084] Path traversal/arbitrary file access | ||
| GRD-131776 | PSIRT: PVR0834883 - [GDP-g085] Command injection | ||
| GRD-131777 | PSIRT: PVR0834884 - [GDP-g086] Cross-site scripting | ||
| GRD-131778 | PSIRT: PVR0834885 - [GDP-g087] Path traversal/arbitrary file access | ||
| GRD-131779 | PSIRT: PVR0834886 - [GDP-g088] Command injection | ||
| GRD-131781 | PSIRT: PVR0834888 - [GDP-g090] Path traversal/arbitrary file access | ||
| GRD-131782 | PSIRT: PVR0834889 - [GDP-g091] Authorization bypass | ||
| GRD-131783 | PSIRT: PVR0834890 - [GDP-g092] Cross-site scripting | ||
| GRD-131784 | PSIRT: PVR0834891 - [GDP-g093] Cross-site scripting | ||
| GRD-131785 | PSIRT: PVR0834892 - [GDP-g094] Unsafe deserialization | ||
| GRD-131787 | PSIRT: PVR0834894 - [GDP-g096] Path traversal/arbitrary file access | ||
| GRD-133543 | PSIRT: PVR0871011 - Tomcat upgrade to version 9.0.120 | CVE-2026-53434, CVE-2026-55276, CVE-2026-59083, CVE-2026-59084 |
Known limitations and workarounds
| Issue key | Summary |
|---|---|
| GRD-132587 | If you use a public simple storage service (S3) with Guardium long term retention, you will experience a timeout when running the store cold_storage catalog_protocol rest command to distribute the datalake-catalog certificate during the upgrade process from Data lake patch 12.0p80111 to Data lake patch 12.0p90230. A fix is available in Guardium Data Protection patch 12.0p234 (see release notes). |
[{"Type":"MASTER","Line of Business":{"code":"LOB76","label":"Data Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSDKGA","label":"IBM Guardium Data Protection"},"ARM Category":[{"code":"a8m3p000000PCTuAAO","label":"Platform\/Installation\/Deployment"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"12.2.3"}]
Was this topic helpful?
Document Information
Modified date:
14 September 2026
UID
ibm17285635