Release Notes
Abstract
This technical note provides guidance for installing IBM Guardium Data Protection patch 12.0p50, including any new features or enhancements, resolved or known issues, or notices associated with the patch.
Content
- Patch file name: SqlGuard-12.0p50_Bundle_Dec_02_2025.tgz.enc.sig
- MD5 checksum: e1220a6acb6c2765fba5c56d1a9ab02a
Finding the patch
- Select the following options to download this patch on the IBM Fix Central website and click Continue.
- Product selector: IBM Security Guardium
- Installed Version: 12.0
- Platform: All
- On the "Identify fixes" page, select Browse for fixes and click Continue.
- On the "Select fixes" page, select Appliance Bundle. Then, enter the patch information in the Filter fix details field to locate the patch.
Installation
- This patch is an appliance bundle that includes all fixes for version 12.0.
- This patch is cumulative and includes all the fixes from previously released patches.
- This patch restarts the Guardium system.
- Do not reboot the appliance while the patch install is in progress. Contact IBM Support if there is an issue with patch installation.
- When changing the password of CLI and guardcli users in the Guardium command line interface, a password strength warning appears even when strong passwords are not enabled. To remove the strong password checks, execute the CLI command store user strong_password disable.
- Download the patch and extract the compressed package outside the Guardium system.
- Review the latest version of the patch release notes just before you install the patch.
- Pick a "quiet" or low-traffic time to install the patch on the Guardium system.
- Apply the latest health check patch.
- Install patches in a top-down manner on all Guardium systems: start with the central manager, then aggregators, then the collectors.
- Apply the latest quarterly DPS patch and rapid response DPS patch even if these patches were applied before the upgrade.
Guardium patch signing certificate expired on 29 March 2025
Guardium appliance patches are signed by an internal certificate to validate that the patch is created by Guardium. Unsigned patch files cannot be installed. The previous patch signing certificate for Guardium appliance patches expired on 29 March 2025.
This patch is signed by the new patch signing certificate. Therefore, to install this patch, your Guardium appliance must be prepared by installing an ad hoc or bundle patch with the fix that allows patches signed by old or new certificates to be installed. See IBM Guardium - Patch signing certificate set to expire in March 2025 and follow the steps in the "What to do after March 29th 2025" section if the patch signing certificate was not renewed.
| Issue key | Summary |
|---|---|
| GRD-95147 | UNIX S-TAP: Use S-TAP Control UI to perform CRUD operations with inspection engine of Oceanbase type |
| GRD-95150 | Add Oceanbase to reports metadata |
| GRD-95152 | Create data source of type Oceanbase for S-TAP verification application type |
| GRD-101168 | Add SSL authentication support for Teradata database connections |
| GRD-110014 | Changes to the outliers‚ input DM from GDP - GDP side |
| Patch | Issue key | Summary | Known issue (APAR) |
|---|---|---|---|
| 12.0p45 | This patch includes fixes from 12.0p45 (see release notes) | ||
| 12.0p50 | GRD-93299 | Vulnerability "HTTP Verb Tampering" observed on Guardium appliances after Penetration Testing | DT439632 |
| GRD-93414 | Missing S3 me-central-1 zone during configuration of backup | DT444696 | |
| GRD-96278 | Adding timestamp, timezone information to universal connector must_gather | N/A | |
| GRD-97815 | Issue with proxy functionality support | N/A | |
| GRD-100655 | LDAP authentication error 'javax.net.ssl.SSLHandshakeException: No appropriate protocol (protocol is disabled or cipher suites are inappropriate)' after enabling only TLS 1.3 protocol on Guardium appliance | DT444915 | |
| GRD-101451 | "Connection closed before we received a valid response" error when saving Data Archive configuration with Dell ECS protocol | DT446545 | |
| GRD-101834 | Version 12 latest bundles reinstall GIM and CAS default certs after the adhoc patch 12.1103 removes them | DT443072 | |
| GRD-102381 | Cannot add multiple remotelog priorities - regex error in remotelog.pl | DT446553 | |
| GRD-102717 | Command 'show remotelog test' sends message with MARK priority to SIEM that was not logged to Guardium messages log file | DT446520 | |
| GRD-102722 | grdapi list_expiration_dates_for_restored_days returns ERR=3000 | DT444670 | |
| GRD-103092 | DPS file upload has wrong file name, wrong version, or wrong date | DT448785 | |
| GRD-103387 | Requesting capability to filter alert messages from syslog included in resulting files from must_gather commands | DT446434 | |
| GRD-103728 | Change tracker alive task might fail in LD due to lack of alive check concurrency with timeout limit | N/A | |
| GRD-104440 | fileserver not working - The URL returned by the fileserver command fails to open | DT447272 | |
| GRD-104758 | LDAP authentication for CLI users not working for appliances with AMD EPYC processors | DT449611 | |
| GRD-105491 | Searching anything in the GUI search bar (User Interface search bar) is not responding | DT451443 | |
| GRD-105633 | Version 12 p35 - Remotelog quit sending syslog events & did not auto-recover | DT450593 | |
| GRD-105885 | Risk Spotter Not Functioning Properly and reports error "Array index out of range: 3 error" | DT448778 | |
| GRD-106072 | Emails sent from the Guardium appliance to external Microsoft email accounts are not received due to bare linefeed error | DT449550 | |
| GRD-106259 | "Test Connection" on Data Archive fails with "Invalid host name" for "AMAZON S3" and "IBM COS" protocols | DT448680 | |
| GRD-106406 | IBM Storage Protect Client installed on Guardium appliance contains libxmlutil library that is vulnerable to several CVEs | DT448724 | |
| GRD-106484 | Error "Unable to connect to UI Server. Verify that server is operational and try again" on the GUI screen attempting to update several datasources in bulk | DT448683 | |
| GRD-106949 | Unable to log in to the GUI on appliance configured to authenticate through SSO SAML | DT448715 | |
| GRD-111470 | PSIRT: PVR0679977 issue with Azure Marketplace image | N/A |
| Patch | Issue key | Summary | CVE |
|---|---|---|---|
| 12.0p45 | This patch includes fixes from 12.0p45 (see release notes) | ||
| 12.0p50 | GRD-100475 | Tenable Scan - protobuf rpm update | CVE-2022-1941 |
| GRD-100564 | Tenable Scan - xdg-utils rpm update | CVE-2022-4055 | |
| GRD-101785 | Qulays Scan : Vim rpm update | CVE-2023-4752 | |
| GRD-109908 | PSIRT: PVR0498314 - easy-rules-mvel-3.2.0.jar (Publicly disclosed vulnerability found by Mend) | CVE-2023-50571 | |
| GRD-105655 | PSIRT: PVR0659972 - MySQL Server July 2025 CPU | CVE-2024-37891, CVE-2025-50076, CVE-2025-50077, CVE-2025-50078, CVE-2025-50079, CVE-2025-50080, CVE-2025-50082, CVE-2025-50083, CVE-2025-50084, CVE-2025-50085, CVE-2025-50086, CVE-2025-50087, CVE-2025-50088, CVE-2025-50089, CVE-2025-50091, CVE-2025-50092, CVE-2025-50093, CVE-2025-50094, CVE-2025-50095, CVE-2025-50096, CVE-2025-50097, CVE-2025-50098, CVE-2025-50099, CVE-2025-50100, CVE-2025-50101, CVE-2025-50102, CVE-2025-50103, CVE-2025-50104, CVE-2025-53023, CVE-2025-53032, CVE-2025-5399 | |
| GRD-100563 | Tenable Scan - git rpm update | CVE-2024-52005, CVE-2025-46835, CVE-2024-50349, CVE-2025-27614, CVE-2025-27613, CVE-2024-52006, CVE-2025-48385, CVE-2025-48384 | |
| GRD-105437 | Tenable Scan - glib2 rpm update | CVE-2024-52533, CVE-2025-4373 | |
| GRD-101791 | Qualys Scan: avahi rpm update | CVE-2024-52616, CVE-2024-52615 | |
| GRD-105440 | Tenable Scan - socat rpm update | CVE-2024-54661 | |
| GRD-102363 | Qulays Scan : libxslt rpm update | CVE-2024-55549 | |
| GRD-100807 | Tenable and Qualys Scan : expat rpm update | CVE-2024-8176 | |
| GRD-100808 | Tenable Scan - glibc rpm update | CVE-2025-0395 | |
| GRD-105564 | Tenable Scan - microcode_ctl update | CVE-2025-20623, CVE-2025-24495, CVE-2024-28956, CVE-2025-20012, CVE-2024-43420, CVE-2024-45332 | |
| GRD-105540 | Tenable Scan - kernel rpm update | CVE-2025-21999, CVE-2025-21979, CVE-2025-21969, CVE-2025-37750, CVE-2025-21961, CVE-2025-21963, CVE-2025-23150, CVE-2025-21883, CVE-2025-22104, CVE-2025-37738, CVE-2023-52933, CVE-2025-21759, CVE-2025-22004, CVE-2025-37799, CVE-2025-21887, CVE-2025-21991, CVE-2024-58002, CVE-2025-38089, CVE-2025-21926, CVE-2025-22055, CVE-2025-37785, CVE-2025-37943, CVE-2025-21920, CVE-2025-21997, CVE-2023-52623, CVE-2024-26638, CVE-2024-41042, CVE-2024-58099, CVE-2023-52662, CVE-2024-35847, CVE-2024-26669, CVE-2024-36917, CVE-2024-56615, CVE-2024-35838, CVE-2024-26939, CVE-2025-21764, CVE-2024-36940, CVE-2024-36006, CVE-2022-49846, CVE-2024-35924, CVE-2024-35807, CVE-2024-43880, CVE-2024-41097, CVE-2023-52477, CVE-2023-52565, CVE-2024-39471, CVE-2024-26717, CVE-2024-41092, CVE-2023-52781, CVE-2023-52595, CVE-2024-35790, CVE-2024-46826, CVE-2024-56614, CVE-2025-22126, CVE-2023-52834, CVE-2025-38110, CVE-2025-22121, CVE-2025-38086, CVE-2024-57980, CVE-2025-22085, CVE-2025-37797, CVE-2025-22091, CVE-2025-37958, CVE-2025-37890, CVE-2025-21727, CVE-2025-22020, CVE-2025-21928, CVE-2025-21929, CVE-2022-49788, CVE-2025-21962, CVE-2025-38052, CVE-2025-21905, CVE-2025-22113, CVE-2025-38087, CVE-2021-47527, CVE-2022-48669, CVE-2022-49395, CVE-2022-49788, CVE-2023-52451, CVE-2023-52764, CVE-2023-52877, CVE-2024-26659, CVE-2024-26934, CVE-2024-26964, CVE-2024-27059, CVE-2024-36945, CVE-2024-43888, CVE-2025-21919, CVE-2022-3424, CVE-2024-58005, CVE-2024-58007, CVE-2024-58069, CVE-2025-21633, CVE-2025-21927, CVE-2025-21993, CVE-2025-21756, CVE-2025-21966, CVE-2025-37749, CVE-2025-21964 | |
| GRD-105434 | PSIRT: PVR0657625 - reactor-netty-http-1.0.7.jar (Publicly disclosed vulnerability found by Mend) | CVE-2025-22227 | |
| GRD-100813 | Tenable Scan - podman update | CVE-2025-22869, CVE-2025-22871, CVE-2025-6032 | |
| GRD-105553 | Tenable Scan - libarchive rpm update | CVE-2025-25724 | |
| GRD-100565 | Tenable Scan - podman rpm update | CVE-2025-27144, CVE-2025-22869 | |
| GRD-100567 | Tenable Scan - buildah rpm update | CVE-2025-27144, CVE-2025-22871 | |
| GRD-105548 | Tenable Scan - sudo rpm update | CVE-2025-32462 | |
| GRD-105544 | Tenable Scan - krb5-libs rpm update | CVE-2025-3576 | |
| GRD-105452 | Tenable Scan - perl-FCGI update | CVE-2025-40907 | |
| GRD-105463 | Tenable Scan - python3 rpm update | CVE-2025-4138, CVE-2025-4435, CVE-2025-4330, CVE-2025-4517, CVE-2024-12718, CVE-2024-11168, CVE-2024-9287 | |
| GRD-105543 | Tenable Scan - iputils rpm update | CVE-2025-47268 | |
| GRD-105470 | Tenable Scan - python3-setuptools rpm update | CVE-2025-47273 | |
| GRD-105443 | Tenable Scan - glibc rpm update | CVE-2025-4802, CVE-2025-5702, CVE-2025-8058 | |
| GRD-105474 | Tenable Scan - jq rpm update | CVE-2025-48060, CVE-2024-23337 | |
| GRD-102092 | PSIRT: PVR0668193 - commons-beanutils-1.9.2.jar (Publicly disclosed vulnerability found by Mend) - Kafka | CVE-2025-48734 | |
| GRD-105431 | PSIRT: PVR0656925 - cxf-core-3.5.10.jar (Publicly disclosed vulnerability found by Mend) | CVE-2025-48795 | |
| GRD-105449 | PSIRT: PVR0656083 - commons-lang-2.3.jar (Publicly disclosed vulnerability found by Mend) | CVE-2025-48924 | |
| GRD-105541 | Tenable Scan - xorg-x11-server update | CVE-2025-49175, CVE-2025-49176, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 | |
| GRD-105482 | Tenable Scan - libxml2 rpm update | CVE-2025-49794, CVE-2025-49796, CVE-2025-6021, CVE-2025-7425 | |
| GRD-105457 | PSIRT: PVR0657567 - nimbus-jose-jwt-9.38.jar (Publicly disclosed vulnerability found by Mend) | CVE-2025-53864 | |
| GRD-109346 | PSIRT : PVR0664972 - netty-codec-http2-4.1.110.Final.jar (Publicly disclosed vulnerability found by Mend) | CVE-2025-55163 | |
| GRD-111590 | PSIRT: PVR0669678, PVR0669059 - netty-codec-4.1.119.Final.jar (Publicly disclosed vulnerability found by Mend) | CVE-2025-58057 | |
| GRD-105546 | Tenable Scan - pam rpm update | CVE-2025-6020 | |
| GRD-106825 | Tenable Scan - sqlite-libs rpm update | CVE-2025-6965 |
| Issue key | Summary |
|---|---|
| GRD-100625 | When you upgrade your environment from any Guardium version 12.0 release to Guardium version 12.1, the following CLI values are not retained and must be set again. store account lockout |
Was this topic helpful?
Document Information
Modified date:
08 January 2026
UID
ibm17252108