User with Inquire Only Access is Able to Create Instances of Business Objects
(Doc ID 2437195.1)
Last updated on NOVEMBER 07, 2018
Applies to:Oracle Utilities Meter Data Management - Version 22.214.171.124.0 and later
Oracle Utilities Framework - Version 126.96.36.199.0 and later
Information in this document applies to any platform.
A user with only Inquire access is able to create a Usage Transaction.
Steps to recreate the issue:
1. Create an application service.
2. Add application service to an user group and grant only Inquire access.
3. Update a business object such that the new application service is populated on it.
4. Flush the cache.
5. Create an instance of the business object you edited in step 3.
For example: Use the Extended Lookup Business Object and create extended lookup record from its portal.
Expected Result: Error should be displayed on page as user does not have sufficient permission.
Actual Result: Record is created successfully.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document