My Oracle Support Banner

Security Issue with Project Specific Landing Area in Oracle EDQ (Doc ID 2161319.1)

Last updated on MAY 19, 2023

Applies to:

Oracle Enterprise Data Quality - Version 12.1.3.0.0 and later
Oracle Enterprise Data Quality on Marketplace - Version 12.2.1.4.3 and later
Information in this document applies to any platform.

Symptoms

In Enterprise Data Quality (EDQ) 12.2.1, Project-Specific landing areas correspond to the internal ID of the projects. However, User A with access only to Project A is still able to create a data store and snapshot files in the landing area of Project B to which they don't have access.

A user can do this by simply unchecking the project-specific landing area checkbox and specifying the path, "\[internal id of Project B\file_name]," assuming User A knows the internal id of Project B. Please note the 'Add Project' permission is not given to the group to which the user belongs.

This is a bug that is fixed in EDQ 12.2.1.2 and later

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.