Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Connection to the SAP virus scan interface, SAP security note 1598308

SAP Note 1598308
SAP Security Note

SAP security note 1598308, "Connection to the SAP virus scan interface", is a note released on 13.12.2011. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Basis Services/Communication Interfaces > Communication Services: Mail, Fax, SMS, Telephony
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on13.12.2011

Description

Symptom

Messages that are received via the SAPconnect SMTP interface cannot be checked for viruses.

Solution

Implement the corrections using the Note Assistant or import the relevant Support Package. This enables the connection to the SAP virus scan interface in SMTP inbound processing. After implementing the corrections, the connection is inactive (the system behaves as before the corrections were applied).

Use transaction VSCANPROFILE to activate and set parameters for the virus scan interface. The profile /SBCOMS/SMTP_INBOUND is relevant for SAPconnect and is created automatically when an e-mail is received via SAPconnect in the current client after applying the corrections.

It’s recommended that SMTP messages are already scanned for viruses in upstream Mail Transfer Agents (MTAs) before they are routed to the SAP system. Carefully assess whether the virus scanner can be used in SAPconnect inbound processing and use it only in exceptional cases.

For more information, refer to SAP Note 639486.

Reason and prerequisites

No connection to the SAP virus scan interface exists.

CVSS

Score 0

References

Full note on SAP: SAP Support Launchpad note 1598308

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More