GetFile Privilege Can Be Bypassed In The View Versions Table For Items
(Doc ID 2830009.1)
Last updated on DECEMBER 22, 2021
Applies to:Oracle Agile Product Collaboration - Version 126.96.36.199 and later
Information in this document applies to any platform.
Users can bypass the privilege mask for GetFile privilege by accessing the file through the View Versions table on the attachment tab of Items.
The Get button should be grayed out for users who do not have the GetFile privilege
- Log into Java client (http://server:port/JavaClient/start.html)
- Select from the Admin tab User Settings > Roles
- Create a new Role
- Add the following privileges to the Role
Modify Preliminary Items
ViewFile Engineering Change
- Save the settings and assign this Role to a test user
- Log into Web Client using the test user (http://server:port/Agile/PLMServlet)
- Opened a Document object D0001234
- Selected Rev 004 from the drop down.
- Get is grayed out and user can not download the file using GET
- Selected from the More > View Versions menu
- User can GET the attachment from the Versions window
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document