My Oracle Support Banner

User with Inquire Only Access is Able to Create Instances of Business Objects (Doc ID 2437195.1)

Last updated on SEPTEMBER 27, 2022

Applies to:

Oracle Utilities Meter Data Management - Version 2.2.0.2.0 and later
Oracle Utilities Framework - Version 4.3.0.5.0 to 4.3.0.5.0 [Release 4.3]
Information in this document applies to any platform.

Symptoms

A user with only Inquire access is able to create a Usage Transaction.

Steps to recreate the issue:

1. Create an application service.
2. Add application service to an user group and grant only Inquire access.
3. Update a business object such that the new application service is populated on it.
4. Flush the cache.
5. Create an instance of the business object you edited in step 3.

For example: Use the Extended Lookup Business Object and create extended lookup record from its portal.

Expected Result: Error should be displayed on page as user does not have sufficient permission. 

Actual Result: Record is created successfully.

 

Changes

 

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Changes
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.