Local Sales Admin can access Opportunities associate with other’s Business Unit

(Doc ID 2108738.1)

Last updated on FEBRUARY 20, 2016

Applies to:

Oracle Fusion Sales Cloud Service - Version 11.1.10.0.0 and later
Information in this document applies to any platform.

Symptoms

On : 11.1.10.0.0 version, Opportunities

 

Customer implemented multiple BUs.

Any they created a hierarchy of organizations and they have associated the organizations with BUs.

Each organization has a manager and a team.

 

Profile Attribute

========================

Manage Common CRM Business Unit Profile Options > HZ_ENABLE_MULTIPLE_BU_CRM = 'Yes'

Manage Common CRM Business Unit Profile Options > HZ_DEFAULT_BU_CRM = 'ROOT BU'

 

Organization Data

======================

- Root Organization

 > Child_1 Organization  (associate with CHILD_1 BU)

 > Child_2 Organization  (associate with CHILD_2 BU)

 

Organization: Root Organization

is associated with BU

> ROOT BU

> CHILD_1 BU

> CHILD_2 BU

 

Opportunity Data

==========================

Name : TEST_Oppty

Opportunity Number : 10001

 

OPTY_ID : 300000001111111

was associated with 'CHILD_1 BU'

 

ACTUAL BEHAVIOR
---------------
Admin_1 who is a Sales Administrator of 'Child_2 Organization'

Is able to search and access 'TEST_Oppty' Opportunity is associate with 'CHILD_1 BU' which in turn belong to 'Child_1 Organization',

even though Opportunity is not part of Admin_1's Organization i.e 'Child_2 Organization'

But, the following document does suggest
Oracle Sales Cloud: Managing Multiple Business Units (Doc ID 2015552.1)

Admin Access. Sales administrators can only access objects in the BUs they are associated with.



EXPECTED BEHAVIOR
-----------------------
Admin_1 should not be able to see Opportunity associate with other's BU.

STEPS
-----------------------
The issue can be reproduced at will with the following steps:

Opportunity > Search >

BUSINESS IMPACT
-----------------------
The issue has the following business impact:
Due to this issue, Sales admin can see others BU data as well.



Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms