Meet the Authors

Key Takeaways What you need to know
  1. bowbridge Anti-Virus for SAP Solutions adds SAP antivirus protection for uploads, attachments, and files moving through SAP application workflows.

  2. The product integrates with SAP NetWeaver Virus Scan Interface to scan content inside SAP NetWeaver and SAP S/4HANA environments.

  3. SAP security teams can use application-layer malware scanning to strengthen upload controls, compliance evidence, and SAP workflow protection.

bowbridge markets Anti-Virus for SAP Solutions as a scanning layer purpose-built for SAP NetWeaver and SAP S/4HANA environments, aimed at catching malware in file uploads and attachments before it reaches SAP data.

Generic endpoint antivirus tools typically monitor the file system and network traffic, not content moving inside SAP application workflows. bowbridge positions its product as closing exactly that gap. That distinction runs through the product’s integration with the SAP NetWeaver Virus Scan Interface, the mechanism SAP built for this purpose.

How SAP’s Virus Scan Interface Enables Scanning

SAP developed NW-VSI as a kernel-level API so external scanning engines could inspect files as they pass through SAP application processes, rather than waiting for them to land on disk. The interface is available for both AS ABAP and AS Java, giving vendors a consistent way to plug into SAP’s processing layer regardless of the underlying stack. bowbridge Anti-Virus for SAP Solutions integrates through NW-VSI and scans files entirely in-memory, an approach the company says avoids writing content to disk mid-scan.

Explore related questions

bowbridge Targets Malware Hidden Inside SAP Files

Generic antivirus tools generally rely on signature matching against known malware files, a method that can miss threats disguised inside application-specific formats. bowbridge describes its product as designed to detect and block cross-site scripting code hidden or obfuscated inside uploaded files.

The company also positions the tool as able to scan the full contents of SAPCAR archives, SAP’s proprietary compression format, for malicious payloads that might otherwise pass through unread. Niclaas Grehling of TÜV Rheinland, a bowbridge customer, said the solution “has proven to be simple to set up and free of additional maintenance effort” in production use.

What This Means for SAPinsiders

  • Application-layer scanning moves from niche to expected practice. SAP’s own guidance has recommended interface-based virus scanning since 2016, well before most compliance mandates caught up. Security teams at large SAP shops increasingly treat NW-VSI configuration as a standard build step, not an optional add-on.
  • Vendor certification records matter more without an active program. With SAP’s NW-VSI certification ended as of December 2023, no vendor can point to a current certification cycle. Buyers comparing SAP security vendors are placing more weight on historical certification depth and interface-version support.
  • Compliance frameworks push malware controls toward applications. Standards such as ISO 27002:2022 Control 8.7 call for defense-in-depth malware protection spanning gateways, not just endpoints. Compliance and GRC teams are increasingly asking application owners to document scanning coverage at the workflow level, alongside traditional endpoint reporting.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All