SAP Knowledge Base Article - Public

2152785 - Default CMS port shared by trojan virus

Symptom

A Trojan called "The Thing" (created May 1999) utilizes the same port as the Central Management Server's default port of 6400.

Environment

  • Windows

Resolution

Though this Trojan was discovered in 1999, it can still be flagged as an issue in vulnerability scans.  For more information, please see:

http://www.simovits.com/trojans/tr_data/y3360.html

Recommended remediation:

  1. Always ensure your anti-virus programs are up to date with the latest definitions
  2. Consider changing the default CMS port to something else in line with your organizational security policy. Please consult the Admin guide for your product for more information on how to accomplish this
    http://help.sap.com/bobi/

Keywords

trojan, virus, 6400, CMS, port, default, Central Management Server, The Thing, Thing , KBA , BI-BIP-INS , Installation, Updates, Upgrade, Patching , Problem

Product

SAP Crystal Server 2011