IBM Security AppScan V9.0 application security portfolio continues to deliver on static, dynamic, and interactive application security testing

Similar documents
IBM Security AppScan V8.8 portfolio supports collaborative and analytical security testing throughout the software development lifecycle

IBM Security AppScan V8.8 portfolio supports collaborative and analytical security testing throughout the software development lifecycle

IBM COBOL for Windows, V7.6 provides a costeffective compiler and runtime environment for customizing third-party applications on Windows servers

Software withdrawal: IBM Rational AppScan selected licenses

IBM WebSphere MQ Hypervisor Edition accelerates deployment of private cloud messaging

IBM DB2 SQL Skin Feature 1.0 for applications compatible with Sybase Adaptive Server Enterprise

IBM WebSphere Application Server Hypervisor Edition for IBM AIX speeds adoption of virtualization and cloud computing in PowerVM environments

IBM InfoSphere Master Content for InfoSphere Master Data Management Server delivers enterprise content to single view of customer applications

IBM Power Systems Software: Ordering and pricing structure enhancements

IBM Parallel Environment for Linux, V4.3 delivers enhancements for IBM System x clusters, including a parallel debugger

IBM Scale Out Network Attached Storage Software

IBM Rational DOORS Web Access V1.3 can help shorten requirements development time

IBM Secure Perspective bridges the gap between data security policy and practice

IBM Rational AppScan automates Web application security testing to identify and help remediate application vulnerabilities

Software withdrawal: IBM Rational Software Analyzer selected licenses

IBM United States Announcement , dated October 9, 2007

IBM UrbanCode Deploy V6.2 provides the tools needed to automate the application deployment pipeline

IBM Lotus Foundations Reach 1.0 delivers instant messaging, unified communications, and collaboration capabilities for small business

IBM System z part numbers available for the IBM WebSphere Business Modeler V products

IBM i operating system Value Pack offers software and vouchers for IBM Power 570 and 595 servers

IBM X.25 over TCP/IP for Communication Controller for Linux lets you use X.25 in the CCL environment

IBM XML Toolkit for z/os, V1.10: Enhanced C++ XML parser and C++ XSLT processor support

IBM Europe, Middle East, and Africa Software Announcement ZP , dated October 2, 2012

IBM Rational Computer Based Training and Rational Web Based Training now available through Passport Advantage

IBM Rational Functional Tester Plus delivers regression testing bundle

IBM Europe, Middle East, and Africa Software Announcement ZP , dated May 3, 2011

IBM Lotus Messaging and WebSphere Portal CEO bundle includes messaging, collaborative applications, and full portal capabilities

IBM DB2 SQL Skin Feature 1.0 for applications compatible with Sybase Adaptive Server Enterprise

IBM WebSphere Business Integration Adapter for DTS Protocol extends legacy mainframe integration

IBM XL Fortran Advanced Edition V8.1 for Mac OS X A new platform supported in the IBM XL Fortran family

IBM Rational Functional Tester Plus V8.2 delivers automated functional testing for client-server, enterprise, and modern web applications

IBM Rational Asset Manager V7.5.2 delivers new features to support DevOps, updated platforms and integrations, and usability improvements

Data Discovery and Query Builder software can simplify time-intensive, costly, and complex ad hoc database query creation

IBM Data Discovery and Query Builder software can simplify time-intensive, costly, and complex ad hoc database query creation

IBM System Storage SAN Volume Controller Entry Edition Software V4.3.1 brings new price option to entry and midrange customers

IBM System Storage ProtecTIER Entry Edition V2.5 supports Symantec NetBackup OpenStorage API

InfoPrint Solutions Company Latin America Software Announcement LP , dated March 16, 2010

IBM Tivoli Risk Manager Provides Protection for the Enterprise through Intrusion and Protection Management

IBM Workplace Client Technology, Micro Edition V5.7 delivers tools and run-times for server-managed client devices

IBM XL Fortran for AIX, V12.1 delivers enhanced parallel programming capability for IBM Power Systems

IBM XL C/C++ Advanced Edition V7.0.1 for Linux and XL Fortran Advanced Edition V9.1.1 for Linux enhanced to include new Linux support

IBM United States Software Announcement , dated June 3, 2013

IBM Content Integrator V8.6 delivers serviceoriented architecture, integration, and performance enhancements

IBM 64-bit SDK for z/os, Java Technology Edition, V6 lets application developers use Java on IBM z/os

IBM Aspera Platform delivers new solutions and bundles for high bandwidth use cases and enhanced ordering flexibility

IBM DB2 High Performance Unload for Multiplatforms and Workgroups add additional language support

Software Announcement January 31, 2006

IBM General Parallel File System for Linux helps simplify file system management across clusters

IBM United States Software Announcement , dated April 23, 2013

IBM WebFacing Deployment Tool V7.0 with HATS technology increases integration for IBM System i modernization solution and rich-client support

IBM ediscovery Analyzer V2.1 - Conceptual search and analysis of cases created by IBM ediscovery Manager

Software Announcement September 23, 2003

IBM Security AppScan now supports SAP code quality and data loss prevention testing with Virtual Forge CodeProfiler for IBM Security AppScan Source

IBM WebSphere Adapters on WebSphere Application Server are designed to accelerate enterprise application suite integration

IBM United States Announcement , dated March 27, 2007

VMware products, available from IBM, provide the latest capabilities for desktop virtualization

IBM United States Announcement , dated March 27, 2007

IBM Optim solutions for z/os for PeopleSoft Enterprise V6.2 include new features, simplified packaging, and new pricing

IBM WebSphere Business Monitor V6.0.2 adds productivity enhancements

IBM WebSphere Service Registry and Repository V8.5.6 offers enhancements to improve REST service support and user productivity

IBM DataPower Gateway X2 Appliance is available through Passport Advantage

IBM Workstation APL2 for Multiplatforms V2 Includes Productivity Enhancements and Linux Support

IBM United States Software Announcement , dated December 9, 2014

IBM Ported Tools for z/os: PHP for z/os Feature V1.1.2

IBM Lotus Protector for Mail Encryption 2.1 extends IBM Lotus Notes integrated encryption to different recipient types

Revised terms and condition: Floating User Licenses for IBM Rational Insight allow additional flexibility in licensing and deploying Insight

IBM Optim Query Workload Tuner for DB2 for z/os, V2.2.1 can help cut cost and improve performance

IBM WebSphere MQ V5.3 Changes to Processor-Based Pricing and Adds Extended Transactional Clients

IBM Rational DOORS V9.3 and IBM Rational DOORS Web Access V The first step to integrate DOORS to IBM Rational Jazz-based systems

IBM WebSphere Everyplace Mobile Portal Enable V6 extends portals to mobile devices

IBM Transparent Data Migration Facility for z/ OS (TDMF z/os) V5.7 delivers data migration enhancements and the z/vm Agent for TDMF z/os

IBM Engineering and Scientific Subroutine Library V4.4 adds new LAPACK and Fourier Transform subroutines

IBM Rational Developer for Power Systems Software V8.0 helps improve developer productivity and adds Linux platform support

WebSphere Application Server, V6.0 Now available for OS/400

IBM XL C/C++ for Linux, V10.1 adds support for OpenMP V3.0 and introduces partial support for C++0x features

IBM WebSphere MQ for HP OpenVMS V6.0 delivers improved ease of use and manageability to offer a flexible, proven foundation for your ESB

IBM Lotus Domino Unified Communication V1.2.2 adds National Language Support and AIX for Cisco

IBM Rational Migration Extensions for CA Technologies V7.5.1 enables flexibility and reduces costs

Integrated Stack for SUSE Linux Enterprise (ISSLE)

IBM United States Software Announcement , dated October 4, 2011

IBM Transparent Data Migration Facility for z/os V5.6 delivers data migration enhancements

IBM Engineering and Scientific Subroutine Library V4.4 adds new LAPACK and Fourier Transform subroutines

ProtecTIER supports Symantec NetBackup OpenStorage API

IBM WebSphere Cast Iron Live V7.5 delivers key enhancements that include improved security capabilities and increased connectivity options

IBM XL Fortran Advanced Edition for Linux, V11.1 exploits the capabilities of the IBM POWER6 processors

IBM United States Software Announcement , dated July 17, 2017

VMware vsphere subscription upgrades available

InfoPrint ProcessDirector now offers Designer and Whitespace Manager

IBM AIXlink/X.25 V2.1 offers enhancements for migration from X.25 specific adapters that allow APIs to remain the same

IBM System Storage SAN Volume Controller Software V4.3.0 introduces space-efficient VDisks and VDisk mirroring

IBM Lotus Web Content Management Feature Pack adds value to your Web sites by simplifying the content creation and management process

IBM WebSphere Voice Application Access V5 with VoiceXML 2.0 support expands speech enablement possibilities for e-business environments

QuickSpecs. Available Packs and Purchase Information. ProLiant Essentials Vulnerability and Patch Management Pack v2.1. Overview.

IBM FileNet Capture V5.2.1 delivers options for language recognition and document format handling

IBM Europe, Middle East, and Africa Software Announcement ZP , dated July 28, 2009

IBM WebSphere Adapters V6.2 on WebSphere Application Server accelerate enterprise application suite integration

IBM System Storage ProtecTIER Appliance Edition V2.3 data deduplication software is enhanced with optional replication functionality

IBM United States Software Announcement , dated May 25, 2010

Software Announcement December 17, 2002

IBM Lotus Instant Messaging and Web Conferencing (Sametime) V6.5.1 provides instant, anytime access to people and information

Transcription:

IBM United States Software Announcement 214-064, dated February 25, 2014 IBM Security AppScan V9.0 application security portfolio continues to deliver on static, dynamic, and interactive application security testing Table of contents 2 Overview 6 Technical information 3 Key prerequisites 9 Ordering information 3 Planned availability date 24 Terms and conditions 3 Description 27 Prices 4 Program number 28 Order now 5 Publications At a glance IBM Security AppScan V9.0 delivers new enhancements: Security AppScan Enterprise supports and manages an application security program, which allows clients to: Classify and prioritize application assets based on business impact. Establish application security assessment processes and policies. Identify areas of highest risk and prioritize remediation. Measure and communicate application security status to stakeholders. Security AppScan Source V9.0 extends mobile application security capabilities by providing: Integration with IBM Worklight and the ability to import Worklight projects. Enhanced JavaScript TM analysis, that includes improved performance and additional language and framework support. Support for the latest Apple mobile technologies, which include ios 7, Xcode 5, and Mac OS 10.9. Analysis support for hybrid mobile applications. Security AppScan Standard V9.0 provides: Extension of support for interactive application security testing (glass box) to Microsoft TM.NET applications. An updated login management view of the configuration dialog box to enable more efficient session. For ordering, contact Your IBM representative or an IBM Business Partner. For more information contact the Americas Call Centers at 800-IBM-CALL (426-2255). Reference: YE001 IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 1

Overview Security AppScan V9.0 application security portfolio continues to deliver on static, dynamic, and interactive application security testing. Security AppScan portfolio provides a platform for centrally managing application security testing and risk management as critical elements of application lifecycle management. New in Version 9.0 Security AppScan Standard V9.0 Security AppScan Standard provides: An extension of support for interactive application security testing (glass box) to Microsoft.NET applications. An updated login management view of the configuration dialog box to enable more efficient session management, such as: Action-based login, which reproduces the user's actual actions in the browser, rather than just the requests, is now exposed in the user interface. You can watch the sequence replayed in the browser. The login sequence is recorded in two forms, action-based (user clicks) and request-based, both of which you can manage through the updated details tab. The new Validate feature replays the login sequence live, tracks cookies, detects the in-session pattern in the final response, and greatly improves insession maintenance during the scan. Security AppScan Enterprise V9.0 Security AppScan Enterprise supports and manages an application security program, which allows you to: Classify and prioritize application assets that are based on business impact. Establish application security assessment processes and policies. Identify areas of highest risk and prioritize remediation. Measure and communicate application security status to stakeholders. Security AppScan Source Security AppScan Source V9.0 provides: Enhanced JavaScript analysis, which includes improved performance and additional language and framework support, which includes support for Cordova, HTML5, JQuery, and JQuery Mobile Integration with IBM Worklight The ability to import and scan Worklight projects A unified, Eclipse-based, plug-in IDE for Worklight and AppScan Source Analysis support for Hybrid applications (HTML/JavaScript and native) and Native applications (Java/Android and Objective-C/iOS) Stand-alone operational mode for AppScan Source for Development. Does not require a connection to AppScan Enterprise Server.) Apple Mac OS support for AppScan Source for Development. Support for the latest Apple mobile technologies that include ios 7, Xcode 5, and Mac OS 10.9. Floating license option for AppScan Source for Automation. Improved installation instructions and workflow that includes new single installer for plug-in and full product and a simplified installation for the plug-in products. IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 2

Key prerequisites IBM Security AppScan V9.0 runs on Macintosh and Linux TM operating systems. For details, refer to the Hardware requirements and Software requirements sections. Planned availability date March 28, 2014: For electronic availability April 25, 2014: For media availability Description Software runs business. From the application that manages temperature in a nuclear power plant to the website that drives and collects all incoming business and reservations, there is one commonality to business success -- the ability for those applications to function correctly. The most efficient way to stay ahead of application security vulnerabilities is to build software securely, from the ground up. The challenge is that many organizations do not know how to design and implement secure applications. The majority of developers are not security experts, and secure coding is historically not identified as a priority. As a result, web-based and nonwebbased applications continue to be deployed with vulnerabilities that put sensitive data at risk of a breach. There is a better way. Because the onerous task of vulnerability identification and remediation cannot be successfully addressed by limited IT security resources, one success path is to engage development in the process of application security by providing tools that fit into the existing environment and workflow. These tools should generate results in a way that is easily understood by all stakeholders: development, security and audit personnel, business owners, and executives. The Security AppScan portfolio provides offerings that support and enhance application security testing across the full application lifecycle. Security AppScan V9.0 is a leading application security test suite designed to help manageability testing throughout the software development lifecycle. AppScan offers a time-saving solution for all types of security testing: outsourced, individual, and enterprise-wide analysis, and for all types of users including application developers, build managers, quality assurance (QA) teams, penetration testers, security auditors, and senior management. The Security AppScan portfolio includes offerings that are used to test all aspects of the application portfolio at any size organization, whether it involves live applications or source code. AppScan validates findings and prioritizes reported results so remediation time is reduced. Reports include issuing advisories and advanced fix recommendations designed to educate and help developers and security auditors remediate the identified vulnerabilities. Security AppScan offerings Security AppScan Standard is a desktop solution that utilizes Interactive Application Security Testing (IAST) and Dynamic Application Security Testing (DAST). The patent-pending glass box feature in IBM Security AppScan Standard provides IAST through run-time analysis - an automated method of combining static and dynamic techniques in real time to improve the accuracy of test results. Benefits of glass box, or interactive testing, include more accurate test results, identification of new threat categories, and the ability to pinpoint specific lines of code and details that facilitate remediation. Security AppScan Enterprise is an enterprise-class solution for application security testing and risk management. Security AppScan Enterprise provides robust IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 3

capabilities for governance and facilitates collaboration between development, quality assurance, and security teams across the organization. It centrally manages dynamic, static, and interactive security assessments. It provides enterprise metrics and trending for monitoring application security program progress. It also integrates with Security QRadar to incorporate application vulnerability data into overall security intelligence. Security AppScan Source analyzes source code during the development and build stages of the application lifecycle to identify security vulnerabilities with Static Application Security Testing (SAST) and integrates security testing with the software development processes and systems. Security AppScan Source supports secure mobile application development with testing for native Apple ios (Objective-C) and Android (Java TM ) applications. Accessibility by people with disabilities A US Section 508 Voluntary Product Accessibility Template (VPAT) containing details on accessibility compliance can be requested at http://www.ibm.com/able/product_accessibility/index.html Section 508 of the US Rehabilitation Act IBM logoed offerings where all components and products, including any third party products, are IBM licensed and warranted should respond to the Section 508 question in this announcement as follows: Security AppScan Standard 9.0 is capable as of March 28, 2014, when used in accordance with associated IBM documentation, of satisfying the applicable requirements of Section 508 of the Rehabilitation Act, provided that any assistive technology used with the product properly interoperates with it. A US Section 508 Voluntary Product Accessibility Template (VPAT) can be requested on the following website http://www.ibm.com/able/product_accessibility/index.html Availability of national languages Language Electronic availability date Chinese (Simplified Han) March 28, 2014 Chinese (Traditional Han) March 28, 2014 English March 28, 2014 Korean March 28, 2014 French March 28, 2014 German March 28, 2014 Italian March 28, 2014 Spanish March 28, 2014 Only IBM Security AppScan March 28, 2014 Enterprise (5724-T52) is translated into Russian. Portuguese (Brazil) March 28, 2014 Japanese March 28, 2014 Program number Program Program number VRM name 5724-T59 9.0.0 IBM Security AppScan Standard 5724-T52 9.0.0 5724-Z34 9.0.0 IBM Security AppScan Source for Automation 5724-Z35 9.0.0 IBM Security AppScan Source for Analysis 5724-Z36 9.0.0 IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 4

5724-Z37 9.0.0 IBM Security AppScan Source for Remediation Education support IBM training provides education to support many IBM offerings. Descriptions of courses for IT professionals and managers are on the IBM training website http://www.ibm.com/services/learning/ Call IBM training at 800-IBM-TEACH (426-8322) for catalogs, schedules, and enrollments. Offering Information Product information is available via the Offering Information website http://www.ibm.com/common/ssi Also, visit the Passport Advantage website http://www.ibm.com/software/passportadvantage Publications The publication, 9.0 Planning and Installation Guide (GC14-7268-13) is shipped with Security AppScan Enterprise V9.0. It can also be found, at electronic availability at the below IBM Publication Center. Other online relevant documentation is available, at electronic availability, at http://www-01.ibm.com/support/knowledgecenter/ssw2nf_9.0.0/ com.ibm.ase.help.doc/helpind ex_ase.html The following PDF publications are shipped with Security AppScan Standard V9.0: IBM Security AppScan Standard 9.0 Getting Started Guide IBM Security AppScan Standard 9.0 Glass Box User Guide for Java platforms IBM Security AppScan Standard 9.0 Glass Box User Guide for.net platforms IBM Security AppScan Standard PowerTools Version 8.6: Authentication Tester User Guide (unchanged since AppScan Standard V8.6) IBM Security AppScan Standard PowerTools Version 8.6: Token Analyzer User Guide (unchanged since AppScan Standard V8.6) The following CHM (HTML Help) documentation is shipped with Security AppScan Standard V9.0: IBM Security AppScan 9.0 Online Help IBM Security AppScan Standard PowerTools Version 8.6: Authentication Tester Online Help IBM Security AppScan Standard PowerTools Version 8.6: Connection Test Online Help IBM Security AppScan Standard PowerTools Version 8.6: EncodeDecode Online Help IBM Security AppScan Standard PowerTools Version 8.6: Expression Test Online Help IBM Security AppScan Standard PowerTools Version 8.6: HTTP Request Editor Online Help IBM Security AppScan Standard PowerTools Version 8.6: Token Analyzer Online Help IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 5

The following PDF publications can be found, at electronic availability, at the below IBM Publication Center: IBM Security AppScan Standard 9.0 Getting Started Guide (SC27-6510) IBM Security AppScan Standard 9.0 User Guide (GI13-2874) IBM Security AppScan Standard 9.0 Glass Box User Guide for Java platforms (SC27-6520) IBM Security AppScan Standard 9.0 Glass Box User Guide for.net platforms (SC27-6530) These documents, and other online, relevant documentation are listed in the Security AppScan Standard Publications library at http://www.ibm.com/support/docview.wss?uid=swg27024868 The following publications are shipped with Security AppScan Source V9.0: IBM Security AppScan Source for Analysis User Guide IBM Security AppScan Source Installation and Administration Guide IBM Security AppScan Source Utilities User Guide These documents and other relevant, online documentation are available, at electronic availability, at http://www.ibm.com/support/knowledgecenter/sss9lm_9.0.0/ com.ibm.rational.appscansrc.sec urity.doc/helpindex.html The IBM Publications Center is available at http://www.ibm.com/shop/publications/order The Publications Center is a worldwide central repository for IBM product publications and marketing material with a catalog of 70,000 items. Extensive search facilities are provided. Payment options for orders are via credit card (in the US) or customer number for 20 countries. A large number of publications are available online in various file formats, and they can all be downloaded by all countries, free of charge. Technical information Specified operating environment Hardware requirements Security AppScan Source V9.0 Disk space: Approximately 3 GB of available hard disk space (4 GB required for installation) Media drive: CD-ROM or DVD-ROM drive Memory: 2 GB of RAM (minimum); 8G of RAM or more recommended Processor: Two CPU For current information about Security AppScan Source 9.0 hardware requirements, at electronic availability, refer to http://www.ibm.com/support/docview.wss?&uid=swg27027486 IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 6

Security AppScan Enterprise V9.0 This configuration supports an average-sized deployment of three to four Dynamic Analysis Scanners (two concurrent scan jobs per scanner). Larger deployments or loads may require more resources. Disk space: Approximately 200 GB for the AppScan Enterprise Server and Jazz TM Team Server Approximately 500 GB of free space for scan logs on the Dynamic Analysis Scanner Approximately 1 TB of free space on the system hosting the SQL Server database Approximately 330 MB for the Web Services Explorer - Generic Service Client tool (GSC) version 8.1 used to test Web Services for security vulnerabilities Memory: 16 GB of RAM (minimum) or more recommended for SQLServer database and Dynamic Analysis Scanner 8 GB of RAM or more recommended AppScan Enterprise Server and Jazz Team Server Processor Four CPU recommended for SQL Server database and Dynamic Analysis Scanner Two CPU recommended for AppScan Enterprise Server and Jazz Team Server For current information about Security AppScan Enterprise 9.0 hardware requirements, at electronic availability, refer to http://www.ibm.com/support/docview.wss?uid=swg27027541 Security AppScan Standard V9.0 Disk space: Approximately 30 GB of available hard disk space Memory: 3 GB of RAM or more recommended NIC network driver: 1 NIC 100 Mbps for network communication with configured TCP/IP Processor: Core 2 Duo 2 GHz (or equivalent) For current information about Security AppScan Standard 9.0 hardware requirements, at electronic availability, refer to http://www.ibm.com/support/docview.wss?uid=swg27024155 Software requirements Security AppScan Source V9.0 For Security AppScan Source software requirements, access http://www.ibm.com/support/docview.wss?&uid=swg27027486 The program's specifications and specified operating environment information may be found in documentation accompanying the program, if available, such as a readme file, or other information published by IBM. Security AppScan Enterprise V9.0 For Security AppScan Enterprise V9.0 software requirements, access http://www.ibm.com/support/docview.wss?uid=swg27027541 IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 7

The program's specifications and specified operating environment information may be found in documentation accompanying the program, if available, such as a readme file, or other information published by IBM, Security AppScan Standard V9.0 For Security AppScan Standard V9.0 software requirements, access http://www.ibm.com/support/docview.wss?uid=swg27024155 The program's specifications and specified operating environment information may be found in documentation accompanying the program, if available, such as a readme file, or other information published by IBM, The program's specifications and specified operating environment information may be found in documentation accompanying the program, if available, such as a readme file, or other information published by IBM, such as an announcement letter. Documentation and other program content may be supplied only in the English language. IBM Electronic Support The IBM Support Portal is your gateway to technical support. This includes IBM Electronic Support tools and resources, for software and hardware, to help save time and simplify support. The Electronic Support tools can help you find answers to questions, download fixes, troubleshoot, automate data collection, submit and track problems through the Service Request online tool, and build skills. All these tools are made available through your IBM support agreement, at no additional charge. Read about the Electronic Support portfolio of tools http://ibm.com/electronicsupport Access the IBM Support Portal http://ibm.com/support Access the online Service Request tool http://ibm.com/support/servicerequest Planning information Software Subscription and Support (also referred to as Software Maintenance) is included with licenses purchased through Passport Advantage and Passport Advantage Express. Product upgrades and technical support are provided by the Software Subscription and Support (Software Maintenance) offering as described in the Agreements. Product upgrades provide the latest versions and releases to entitled software, and technical support provides voice and electronic access to IBM support organizations, worldwide. IBM includes one year of Software Subscription and Support (also referred to as Software Maintenance) with each program license acquired. The initial period of Software Subscription and Support (Software Maintenance) can be extended by the purchase of a renewal option, if available. Packaging Security AppScan is distributed with: International Program License Agreement (Z125-3301) License Information document DVDs Publications (refer to the Publications section) IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 8

This program, when downloaded from a website, contains the applicable IBM license agreement and License Information, if appropriate, and will be presented for acceptance at the time of installation of the program. For future reference, the license and License Information will be stored in a directory such as LICENSE.TXT. Software Services IBM Software Services has the breadth, depth, and reach to manage your services needs. You can leverage the deep technical skills of our lab-based, software services team and the business consulting, project management, and infrastructure expertise of our IBM Global Services team. Also, we extend our IBM Software Services reach through IBM Business Partners to provide an extensive portfolio of capabilities. Together, we provide the global reach, intellectual capital, industry insight, and technology leadership to support a wide range of critical business needs. To learn more about IBM Software Services or to contact a Software Services sales specialist, visit http://www.ibm.com/software/sw-services/ Ordering information This product is only available via Passport Advantage. It is not available as shrinkwrap. These products may only be sold directly by IBM or by authorized IBM Business Partners for Software Value Plus. For more information about IBM Software Value Plus, visit http://www.ibm.com/partnerworld/page/svp_authorized_portfolio To locate IBM Business Partners for Software Value Plus in your geography for a specific Software Value Plus portfolio, visit http://www.ibm.com/partnerworld/wps/bplocator/ Product group: IBM Security AppScan Product Identifier Description (PID) V9.0 5724-T52 IBM Security AppScan Source for Automation V9.0 5724-Z34 IBM Security AppScan Source for Analysis V9.0 5724-Z35 V9.0 5724-Z36 IBM Security AppScan Source for Remediation V9.0 5724-Z37 IBM Security AppScan Standard V9.0 5724-T59 Product category: Security AppScan Passport Advantage Cross-platform product for use on System z Order the part number for System z part numbers below when the product is used for either the development of code that will be deployed on System z servers or when the product will be communicating or transferring data between a distributed server and a System z server. Otherwise order from the other set of part numbers below. This set of System z part numbers provides the identical supply and authorization as the other part numbers below. IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 9

Security AppScan Enterprise (5724-T52) Security AppScan Enterprise Reporting Only Description Reporting Only User Authorized User Single Install License + Reporting Only User Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months Reporting Only User Authorized User Single Install Reporting Only User License + Reporting Only User Annual SW Subscription & Support Renewal 12 Months Reporting Only User Reporting Only User for System z Authorized User Single Install License + Reporting Only User for System z Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months Reporting Only User for System z Authorized User Single Install Reporting Only User for System z License + Reporting Only User for System z Annual SW Subscription & Support Renewal 12 Months Reporting Only User for System z Part number D056CLL E05ELLL D056DLL D07YELL E06GHLL D07YFLL D0569LL E05EJLL D056ALL D07YCLL E06GGLL D07YDLL Fixed term licenses Reporting Only User Authorized User Single Install Initial Fixed Term License + Reporting Only User Authorized User Single Install Subsequent Fixed Term License + D056BLL E05EKLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 10

Reporting Only User Initial Fixed Term License + Reporting Only User Subsequent Fixed Term License + Reporting Only User for System z Initial Fixed Term License + Reporting Only User For System z Subsequent Fixed Term License + Reporting Only User for System Z Authorized User Single Install Initial Fixed Term License + Reporting Only User for System z Authorized User Single Install Subsequent Fixed Term License + D0L7GLL E0CRTLL D0L7HLL E0CRULL D0L7FLL E0CRSLL Security AppScan Enterprise (5724-T52) Security AppScan Enterprise Dynamic Analysis Scanner Dynamic Analysis Scanner Install License + Dynamic Analysis Scanner Install Annual SW Subscription & Support Renewal 12 Months Dynamic Analysis Scanner Install Dynamic Analysis Scanner for System Z Install License + Dynamic Analysis Scanner for System Z Install Annual SW Subscription & Support Renewal 12 Months Dynamic Analysis Scanner for System Z Install SW Subscription & Support Reinstatement 12 Months D0L73LL E0CRJLL D0L74LL D0L75LL E0CRKLL D0L76LL Fixed term licenses Dynamic Analysis Scanner Install Initial Fixed Term License + Dynamic Analysis Scanner Install Subsequent Fixed Term License + D0L7DLL E0CRQLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 11

Dynamic Analysis Scanner for System Z Install Initial Fixed Term License + SW Subscription & Support 12 Month Dynamic Analysis Scanner for System Z Install Subsequent Fixed Term License + D0L7ELL E0CRRLL Security AppScan Enterprise (5724-T52) Security AppScan Enterprise Dynamic Analysis Users Authorized User Single Install License + Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months Authorized User Single Install License + Annual SW Subscription & Support Renewal 12 Months for System z Authorized User Single Install License + for System z Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months for System z Authorized User Single Install for System z License + for System z Annual SW Subscription & Support Renewal 12 Months for System z D61V2LL E047CLL D61V4LL D07YALL E06GFLL D07YBLL D61V3LL E047DLL D61V5LL D07Y8LL E06GELL D07Y9LL Fixed term licenses Initial Fixed Term License + Subsequent Fixed Term License + D0L7KLL E0CRXLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 12

for System z Initial Fixed Term License + for System z Subsequent Fixed Term License + Authorized User Single Install Initial Fixed Term License + Authorized User Single Install Subsequent Fixed Term License + for System z Authorized User Single Install Initial Fixed Term License + for System z Authorized User Single Install Subsequent Fixed Term License + D0L7LLL E0CRYLL D040HLL E04SILL D0L7JLL E0CRWLL Security App Scan Enterprise (5724-T52) Security AppScan Enterprise Server Basic Server Basic Install License + Server Basic Install Annual SW Subscription & Support Renewal 12 Months Server Basic Install Server Basic for System z Install License + Server Basic for System z Install Annual SW Subscription & Support Renewal 12 Months Server Basic for System z Install D0L6CLL E0CRBLL D0L6DLL D0L6ELL E0CRCLL D0L6FLL Fixed Term Licenses Server Basic Install Initial Fixed Term License + Server Basic Install Subsequent Fixed Term License + Server Basic for System z Install Initial Fixed Term License + Server Basic for System z Install Subsequent Fixed Term License + D0L79LL E0CRLLL D0L7ALL E0CRMLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 13

Security App Scan Enterprise (5724-T52) Security AppScan Enterprise Server Server Install License + Server Install Annual SW Subscription & Support Renewal 12 Months Server Install Server for System Z Install License + Server for System Z Install Annual SW Subscription & Support Renewal 12 Months Server for System Z Install D0L6GLL E0CRDLL D0L6HLL D0L6JLL E0CRELL D0L6KLL Fixed term licenses Server Install Initial Fixed Term License + Server Install Subsequent Fixed Term License + Server for System Z Install Initial Fixed Term License + Server for System Z Install Subsequent Fixed Term License + D0L7BLL E0CRNLL D0L7CLL E0CRPLL Security AppScan Source for Automation (5724-Z34) IBM Security AppScan Source for Automation Install License + IBM Security AppScan Source for Automation Install Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Automation Install IBM Security AppScan Source for Automation for System z Install License + IBM Security AppScan Source for Automation for System z Install Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Automation for System z Install IBM Security AppScan Source for Automation per License + IBM Security AppScan Source for Automation per SW Subscription & Support Reinstatement 12 Months IBM Security AppScan Source for Automation per for System z License + D0BQVLL E086LLL D0BQWLL D0CHBLL E08K9LL D0CHCLL D13UKLL D13ULLL D13UMLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 14

IBM Security AppScan Source for Automation per for System z D13UNLL IBM Security AppScan Source for Automation per Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Automation per for System z Annual SW Subscription & Support Renewal 12 Months E0J86LL E0J87LL Fixed term licenses IBM Security AppScan Source for Automation for System z Install Initial Fixed Term License + IBM Security AppScan Source for Automation for System z Install Subsequent Fixed Term License + IBM Security AppScan Source for Automation Install Initial Fixed Term license + IBM Security AppScan Source for Automation Install Subsequent Fixed Term License + IBM Security AppScan Source for Automation per Initial Fixed Term License + SW Subscription & Support 12 Months IBM Security AppScan Source for Automation per for System z Initial Fixed Term License + IBM Security AppScan Source for Automation per Subsequent Fixed Term License + IBM Security AppScan Source for Automation per for System z Subsequent Fixed Term License + D0CHELL E08KBLL D0BR8LL E086ULL D13UILL D13UJLL E0J84LL E0J85LL Security AppScan Source for Development (5624-Z36) Authorized User Single Install License + Authorized User Single Install Annual SW Subscription & Support Renewal Authorized User Single Install for System z Authorized User Single Install License + for System z Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months D0BQZLL E086NLL D0BR0LL D0CHTLL E08KKLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 15

for System z Authorized User Single Install License + Annual SW Subscription & Support Renewal 12 Months for System z License + for System z Annual SW Subscription & Support Renewal 12 Months for System z D0CHULL D0BQXLL E086MLL D0BQYLL D0CHXLL E08KMLL D0CHYLL Fixed term licenses Authorized User Single Install Initial Fixed Term License + Authorized User Single Install Subsequent Fixed Term License + Initial Fixed Term License + Subsequent Fixed Term License + for System z Authorized User Single Install Initial Fixed Term License + for System z Authorized User Single Install Subsequent Fixed Term License + for System z Initial Fixed Term License + for System z Subsequent Fixed Term License + D0BRALL E086WLL D0BR9LL E086VLL D0CIELL E08KWLL D0CIFLL E08KXLL Security AppScan Source for Remediation (5724-Z37) IBM Security AppScan Source for Remediation Authorized User Single Install License + D0BR3LL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 16

IBM Security AppScan Source for Remediation Authorized User Single Install Annual SW Subscription & Support Renewal12 Months IBM Security AppScan Source for Remediation Authorized User Single Install IBM Security AppScan Source for Remediation for System z Authorized User Single Install License + IBM Security AppScan Source for Remediation for System z Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Remediation for System z Authorized User Single Install IBM Security AppScan Source for Remediation License + IBM Security AppScan Source for Remediation Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Remediation IBM Security AppScan Source for Remediation for System z License + IBM Security AppScan Source for Remediation for System z Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Remediation for System z E086QLL D0BR4LL D0CI1LL E08KNLL D0CI2LL D0CI7LL E08KTLL D0CI8LL D0CIBLL E08KVLL D0CICLL Fixed term licenses IBM Security AppScan Source for Remediation Authorized User Single Install Initial Fixed Term License + IBM Security AppScan Source for Remediation Authorized User Single Install Subsequent Fixed Term License + IBM Security AppScan Source for Remediation Initial Fixed Term License + IBM Security AppScan Source for Remediation Subsequent Fixed Term License + IBM Security AppScan Source for Remediation for System z Authorized User Single Install Initial Fixed Term License + SW Subscription & Support 12 Months IBM Security AppScan Source for Remediation for System z Authorized User Single Install Subsequent Fixed Term License + D0BRCLL E086YLL D0CIGLL E08KYLL D0CI4LL E08KQLL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 17

IBM Security AppScan Source for Remediation for System z Initial Fixed Term License + IBM Security AppScan Source for Remediation for System z Subsequent Fixed Term License + D0CIALL E08KULL Security AppScan Source for Analysis (5724-Z35) IBM Security AppScan Source for Analysis Authorized User Single Install License + SW Subscription & Support 12 Months IBM Security AppScan Source for Analysis Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Analysis Authorized User Single Install SW Subscription & Support Reinstatement 12 Months IBM Security AppScan Source for Analysis License + IBM Security AppScan Source for Analysis Annual SW Subscription & Support Renewal12 Months IBM Security AppScan Source for Analysis IBM Security AppScan Source for Analysis for System z Authorized User Single Install License + IBM Security AppScan Source for Analysis for System z Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Analysis for System z Authorized User Single Install IBM Security AppScan Source for Analysis for System z License + IBM Security AppScan Source for Analysis for System z Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Source for Analysis for System z D0BQTLL E086KLL D0BQULL D0CHKLL E08KGLL D0CHLLL D0CHILL E08KFLL D0CHJLL D0CHPLL E08KILL D0CHQLL Fixed term licenses IBM Security AppScan Source for Analysis Authorized User Single Install Initial Fixed Term License + D0BR7LL IBM Security AppScan Source for Analysis E086TLL Authorized User Single Install Subsequent Fixed Term License + IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 18

IBM Security AppScan Source for Analysis Initial Fixed Term License + IBM Security AppScan Source for Analysis Subsequent Fixed Term License + IBM Security AppScan Source for Analysis for System z Authorized User Single Install Initial Fixed Term License + IBM Security AppScan Source for Analysis for System z Authorized User Single Install Subsequent Fixed Term License + IBM Security AppScan Source for Analysis for System z Initial Fixed Term License + IBM Security AppScan Source for Analysis for System z Subsequent Fixed Term License + D0CHHLL E08KELL D0CHFLL E08KCLL D0CHGLL E08KDLL Security AppScan Standard (5724-T59) IBM Security AppScan Standard Authorized User Single Install Annual SW S&S Rnwl 12 Mo IBM Security AppScan Standard Authorized User Single Install Lic + SW S&S 12 Mo IBM Security AppScan Standard Authorized User Single Install SW S&S Reinstate 12 Mo IBM Security AppScan Standard for System Z Authorized User Single Install License + IBM Security App Scan Standard for System Z Authorized User Single Install IBM Security App Scan Standard for System Z Authorized User Single Install Annual SW Subscription & Support Renewal 12 Months IBM Security AppScan Standard Floating User Single Inst Annual SW S&S Rnwl 12 Mo IBM Security AppScan Standard Floating User Single Inst Lic + SW S&S 12 Mo IBM Security AppScan Standard Floating User Single Inst SW S&S Reinstate 12 Mo IBM Security AppScan Standard for System z Annual SW S&S Renewal 12 Months IBM Security AppScan Standard for System z License + SW S&S 12 Months IBM Security AppScan Standard Linux for System z SW S&S Reinstatement 12 Months E0D71LL D0N1KLL D0N1LLL D0N1MLL D0N1NLL E0D72LL E046DLL D61SYLL D61SZLL E046ELL D61T0LL D61T1LL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 19

Fixed term licenses IBM Security AppScan Standard Floating User Single Install Initial Fixed Term License + IBM Security AppScan Standard Subsq FT Lic+S&S 12 Mo IBM Security AppScan Standard for System Z Initial Fixed Term License + IBM Security AppScan Standard for System Z Subsequent Fixed Term License + IBM Security AppScan Standard Authorized User Single Install Initial Fixed Term License + IBM Security AppScan Standard Authorized User Single Install Subsequent Fixed Term License + IBM Security AppScan Standard for System Z Authorized User Single Install Initial Fixed Term License + IBM Security AppScan Standard for System Z Authorized User Single Install Subsequent Fixed Term License + D040CLL E04SDLL D0NEKLL E0DBCLL D0N1PLL E0D73LL D0N1QLL E0D74LL Passport Advantage trade up You must have previously acquired licenses for the following precursor products to be eligible to acquire equivalent licenses of the trade-up products. Trade-up product from precursor product description Server Install FROM Server Basic Per Install Trade-up License + Authorized User Single Install FROM Reporting Only User Per Trade-up License + Trade-up part number D0L6ILL D0L6SLL D0L6RLL FROM IBM Security AppScan Dynamic Analysis User Per Authorized User Single Install Trade-up License + SW Subscription & Support 12 Months FROM Reporting Only User per Trade-up License + Reporting Only User FROM Reporting Only User Authorized User Single Install Trade-up License + D0L6ZLL D0L77LL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 20

Floating User FROM IBM Security AppScan Source for Remediation Floating User Trade-up License + SW Subscription & Support 12 Months Authorized User FROM IBM Security AppScan Source for Remediation per Authorized User Trade-up License + SW Subscription & Support 12 Months Floating User FROM Security AppScan Source Edition for Development Authorized User Trade-up License + SW Subscription & Support 12 Months IBM Security AppScan Source for Remediation Floating User FROM Security AppScan Source for Remediation Authorized User Trade-up License + SW Subscription & Support 12 Months IBM Security AppScan Source for Analysis FROM IBM Security AppScan Source for Analysis Authorized User Single Install Trade-up License + Reporting Only User FROM Security AppScan Enterprise Reporting Only User for System z Authorized Single Install Trade Up License + for System Z Authorized User Single Install FROM Security AppScan Enterprise Reporting Only User per Authorized User Single Install Trade Up License + for System Z FROM Security AppScan Enterprise Dynamic Analysis User Authorized User Single Install Trade Up License + for System Z FROM Security AppScan Enterprise Reporting Only User Trade Up License + Server for System Z Install FROM Security AppScan Enterprise Server Basic Per Install Trade Up License + for System z Authorized User Single Install FROM Security AppScan Source for Remediation Per Authorized User Single Install Trade Up License + for System z FROM Security AppScan Source for Remediation per Trade Up License + D0CIJLL D0CILLL D0CIKLL D0CI9LL D0CHMLL D0L78LL D0L6WLL D0L6VLL D0L72LL D0L6LLL D0CHVLL D0CI0LL IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 21

for System z FROM Security AppScan Source for Development Authorized User Single Install Trade Up License + IBM Security AppScan Source for Remediation for System z FROM Security AppScan Source for Remediation Authorized User Single Install Trade Up License + IBM Security AppScan Source for Analysis for System z FROM Security AppScan Source for Analysis Authorized User Single Install Trade Up License + IBM Security AppScan Standard FROM IBM Security AppScan Standard Auth User Single Install Trade-up License + IBM Security AppScan Standard for System Z FROM IBM Security AppScan Standard Auth User Single Install Trade-up License + D0CHZLL D0CIDLL D0CHRLL D053YLL D053XLL Consult your IBM representative if you have any questions. Passport Advantage customer: Media pack entitlement details Customers with active maintenance or subscription for the products listed are entitled to receive the corresponding media pack. Description and Remediation V9.0 Multilingual, DVD Media Pack IBM Security AppScan Source for Analysis V9.0 Multilingual, DVD Media Pack IBM Security AppScan Source for Automation V9.0 Multilingual, DVD Media Pack Server V9.0 ML Multilingual, DVD Media Pack IBM Security AppScan Standard V9.0 Multilingual, DVD Media Pack Dynamic Analysis Scanner V9.0 Multilingual, DVD Media Pack Part number BT014ML BT013ML BT015ML BT0KUML BJ15HML BT0KVML Charge metric PID Program name number Charge metric IBM Security AppScan Standard V9.0 IBM Security AppScan Enterprise V9.0 Dynamic Analysis Users IBM Security AppScan Enterprise V9.0 Dynamic Analysis Scanner 5724-T59 Authorized User Single Install 5724-T52 Authorized User Single Install 5724-T52 Install IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 22

IBM Security AppScan Source 5724-Z34 for Automation V9.0 IBM Security AppScan Source 5724-Z34 Install for Automation V9.0 IBM Security AppScan Source 5724-Z35 Authorized User Single Install for Analysis V9.0 IBM Security AppScan Source 5724-Z36 Authorized User Single Install for Development V9.0 IBM Security AppScan Source 5724-Z37 Authorized User Single Install for Remediation V9.0 Authorized User Single Install Authorized User Single Install is a unit of measure by which the program can be licensed. An Authorized User is a unique person who is given access to the program. The program may be installed on any number of computers or servers and each Authorized User may have simultaneous access to any number of instances of the program at one time. Licensee must obtain separate, dedicated entitlements for each Authorized User given access to the program in any manner directly or indirectly (for example, via a multiplexing program, device, or application server) through any means. An entitlement for an Authorized User Single Install is unique to that Authorized User and may not be shared, nor may it be reassigned other than for the permanent transfer of the Authorized User entitlement to another person. Note: Some programs may be licensed where devices are considered users. In that case, the following applies. Any computing device that requests the execution of or receives for execution a set of commands, procedures, or applications from the program or that is otherwise managed by the program is considered a separate user of the program and requires an entitlement as if that device were a person. is a unit of measure by which the program can be licensed. A is a person who is accessing the program at any particular point in time. An install is an installed copy of the program on a physical or virtual disk made available to be executed on a computer. The program may be installed on any number of computers or servers, but if the Floating User simultaneously accesses more than one install of the program, the Floating User requires a separate entitlements for each such install. Licensee must obtain separate entitlements for each Floating User simultaneously accessing the program on each install in any manner directly or indirectly (for example, via a multiplexing program, device, or application server) through any means. Note: Some programs may be licensed where devices are considered users. In that case, the following applies. Any computing device that requests the execution of or receives for execution a set of commands, procedures, or applications from the program or that is otherwise managed by the program is considered a separate user of the program and requires an entitlement as if that device were a person. Install Install is a unit of measure by which the program can be licensed. An install is an installed copy of the program on a physical or virtual disk made available to be executed on a computer. Licensee must obtain an entitlement for each install of the program. IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 23

Terms and conditions The information provided in this announcement letter is for reference and convenience purposes only. The terms and conditions that govern any transaction with IBM are contained in the applicable contract documents such as the IBM International Program License Agreement, IBM International Passport Advantage Agreement, and the IBM Agreement for Acquisition of Software Maintenance. This product is only available via Passport Advantage. Licensing IBM International Program License Agreement including the License Information document and Proof of Entitlement (PoE) govern your use of the program. PoEs are required for all authorized use. Part number products only, offered outside of Passport Advantage, where applicable, are license only and do not include Software Maintenance. This software license includes Software Subscription and Support (also referred to as Software Maintenance). These programs are licensed under the IBM Program License Agreement (IPLA) and the associated Agreement for Acquisition of Software Maintenance, which provide for support with ongoing access to releases and versions of the program. IBM includes one year of Software Subscription and Support (also referred to as Software Maintenance) with the initial license acquisition of each program acquired. The initial period of Software Subscription and Support (also referred to as Software Maintenance) can be extended by the purchase of a renewal option, if available. These programs have a one-time license charge for use of the program and an annual renewable charge for the enhanced support that includes telephone assistance (voice support for defects during normal business hours), as well as access to updates, releases, and versions of the program as long as support is in effect. License Information number IBM Security AppScan Standard V9.0 (L-KKHS-9E3P6Q) V9.0 (L-KKHS-9E3PCG) Dynamic Scanner V9.0 (L-KKHS-9E3PEK) IBM Security AppScan Source V9.0 (L-NLII-9DNMDR) The program's License Information will be available for review on the IBM Software License Agreement website http://www.ibm.com/software/sla/sladb.nsf Limited warranty applies Yes Limited warranty IBM warrants that when the program is used in the specified operating environment, it will conform to its specifications. The warranty applies only to the unmodified portion of the program. IBM does not warrant uninterrupted or error-free operation of the program or that IBM will correct all program defects. You are responsible for the results obtained from the use of the program. IBM provides you with access to IBM databases containing information on known program defects, defect corrections, restrictions, and bypasses at no additional charge. IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 24

For further information, consult the IBM Software Support Handbook found at http://www.ibm.com/support/handbook IBM will maintain this information for at least one year after the original licensee acquires the program (warranty period). Program technical support This technical support allows you to obtain assistance (via telephone or electronic means) from IBM for product-specific, task-oriented questions regarding the installation and operation of the program product. Software Subscription and Support (Software Maintenance) also provides you with access to updates (modifications or fixes), releases, and versions of the program. You will be notified, via announcement letter, of discontinuance of support with 12 months' notice. If you require additional technical support from IBM, including an extension of support beyond the discontinuance date, contact your IBM representative or IBM Business Partner. This extension may be available for a fee. Money-back guarantee If for any reason you are dissatisfied with the program and you are the original licensee, you may obtain a refund of the amount you paid for it, if within 30 days of your invoice date you return the program and its PoE to the party from whom you obtained it. If you downloaded the program, you may contact the party from whom you acquired it for instructions on how to obtain the refund. For clarification, note that (1) for programs acquired under the IBM International Passport Advantage offering, this term applies only to your first acquisition of the program and (2) for programs acquired under any of IBM's On/Off Capacity on Demand (On/Off CoD) software offerings, this term does not apply since these offerings apply to programs already acquired and in use by you. Volume orders (IVO) No Passport Advantage applies Yes, and through the Passport Advantage website at http://www.ibm.com/software/passportadvantage Software Subscription and Support applies Yes. Software Subscription and Support (also referred to as Software Maintenance) is included with licenses purchased through Passport Advantage and Passport Advantage Express. Product upgrades and Technical Support are provided by the Software Subscription and Support offering as described in the Agreements. Product upgrades provide the latest versions and releases to entitled software and Technical Support provides voice and electronic access to IBM support organizations, worldwide. IBM includes one year of Software Subscription and Support with each program license acquired. The initial period of Software Subscription and Support can be extended by the purchase of a renewal option, if available. While your Software Subscription and Support is in effect, IBM provides you assistance for your routine, short duration installation and usage (how-to) questions, and code-related questions. IBM provides assistance via telephone and, if available, electronic access, only to your information systems (IS) technical support personnel during the normal business hours (published prime shift hours) of your IBM support center. (This assistance is not available to your end users.) IBM provides Severity 1 assistance 24 hours a day, 7 days a week. IBM United States Software Announcement 214-064 IBM is a registered trademark of International Business Machines Corporation 25