User with Inquire Only Access is Able to Create Instances of Business Objects
(Doc ID 2437195.1)
Last updated on MAY 18, 2021
Applies to:Oracle Utilities Meter Data Management - Version 220.127.116.11.0 and later
Oracle Utilities Framework - Version 18.104.22.168.0 and later
Information in this document applies to any platform.
A user with only Inquire access is able to create a Usage Transaction.
Steps to recreate the issue:
1. Create an application service.
2. Add application service to an user group and grant only Inquire access.
3. Update a business object such that the new application service is populated on it.
4. Flush the cache.
5. Create an instance of the business object you edited in step 3.
For example: Use the Extended Lookup Business Object and create extended lookup record from its portal.
Expected Result: Error should be displayed on page as user does not have sufficient permission.
Actual Result: Record is created successfully.
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document