You are on page 1of 4

Problem Overview

================
Product: IBM Security Guardium
Release: 11.4
Fix ID#: Guardium v11.4 Windows GIM v11.4.0.182
Fix Completion Date: 2021-12-15

Filename: GIM-Installer-11.4_r110400182_1.zip
MD5Sum: 4cc80fe9a996ca338adfecacea93e79d

Filename: guard-GIM-11.4_r110400182_1-x86_x64.gim
MD5Sum: d6b3e07131be8e7efbe550bc5f519dc2

Filename: guard-GIM-guardium_11.4_r110400182_1-Windows-Server-Windows-
x86_x64.exe.signed
MD5Sum: 5ecb91fea10a21d170b5eb77f4803659

Filename: conf.reload.FAM
MD5Sum: c6307cf1323730fbe06ca9c5f70773b5

Filename: guard-FAM-11.4_r110400182_1-x86_x64.gim
MD5Sum: 88bfd61d813eee59c2f363c7aba504e7

Filename: guard-FAM-guardium_11.4_r110400182_1-Windows-Server-Windows-
x86_x64.exe.signed
MD5Sum: 30bc45b70a373ad4be658e8b2812b932

Filename: guard-GUC-11.4_r110400182_1-x86_x64.gim
Md5Sum: c195e957822224397d45c3230a96877a

Filename: guard-GUC-guardium_11.4_r110400182_1-Windows-Server-Windows-
x86_x64.exe.signed
Md5Sum: 280d31ce8d7c4ce6f8dade5e6804a22a

1
Finding the Fix/Patch
=============================
This document is intended to provide a reference to the contents of this fix/patch. If
applicable, the detailed description of each fix and instructions for applying this fix/patch
are contained within the download package. The actual package is available for
downloading from the IBM Fix Central web site at
https://www.ibm.com/support/fixcentral/

Make the following selections on Fix Central:


Product Group: IBM Security
Product Selector: IBM Security Guardium
Installed Version: 11.0
Platform: Windows
Heading: Database Agent (S-TAP, GIM, CAS)

Click "Continue", then select "Browse for fixes" and click "Continue" again.

2
Bugs fixed - Guardium v11.4 Windows GIM 11.4.0.182

Fixed As Of Defect # APAR Description

V11.4.0.168 GRD-48138 Updated OpenSSL to include latest fixes

V11.4.0.182 GRD-55018 Updated OpenSSL to include latest fixes

Bugs fixed - Guardium v11.4 Windows FAM Crawler 11.4.0.182

Fixed As Of Defect # APAR Description

V11.4.0.160 GRD-50435 Fixed connection to Guardium server when multiple


collectors are specified

V11.4.0.182 GRD-57417 Removed JndiLookup class from the classpath: zip -q -d


log4j-core-*.jar
org/apache/logging/log4j/core/lookup/JndiLookup.class
to address Global threat CVE: Log4j - CVE-2021-44228
(Publicly disclosed vulnerability) as described by Apache
Logging Services

https://logging.apache.org/log4j/2.x/security.html

Note:
No fixes were added to GUC build v11.4.0.182 since v11.4.0.168. For customers
currently running GUC v11.4.0.168 or newer, upgrade to GUC v11.4.0.182 is
optional.

Known Issues:

• Guardium Universal Connector parameter configuration during initial installation


is not reflected in the configuration files. To update the parameters successfully,
an additional parameter update is required using GIM Set up by Client

• The status of a Guardium Universal Connector remains Active after the


connection to the data source is deleted

• FAM crawler entry in the S-TAP control page is not cleared following failover to
another collector

3
2021-December-15
IBM Guardium Version 11.x Licensed Materials - Property of IBM. © Copyright IBM Corp. 2002, 2021. US Government
Users Restricted Rights - Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.
IBM, the IBM logo, and ibm.com® are trademarks or registered trademarks of International Business Machines Corp.,
registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other
companies. A current list of IBM trademarks is available on the Web at “Copyright and trademark information”
(www.ibm.com/legal/copytrade.shtml)

You might also like