HR's Able To Edit Personal Payment Method In Personal Info (Doc ID 2250210.1)

Last updated on APRIL 20, 2017

Applies to:

Oracle Fusion Global Payroll Cloud Service - Version 11.1.11.1.0 and later
Information in this document applies to any platform.

Symptoms

On : 11.1.11.1.0 version, Global Payroll

ACTUAL BEHAVIOR
---------------
HR's able to edit Personal Payment Method in Personal info

Our Employees does not have access to edit Personal Payment method under Payroll in Personal information. We are facing issue with HR's who are employees as well is able to edit the Payment method under Personal information.
Our custom employee role does not have access to "Manage Personal Payment Method". So it works as expected for employees
Our Custom HR role have access to "Manage Personal Payment Method" . But HR person security profile enabled access only to HR's security perimeter (based on AOR/global) but we have restricted access to Own record to all the HR's. When HR tried to search for them selves in Person management, it didn't retrieve result. So security works fine.
When they navigate to Personal information >> Payroll >> there is no Manage button.. Which is fine. But if they click on the name, it is allowing then to edit their bank details and name.

EXPECTED BEHAVIOR
-----------------------
HR should not have access to personal payment method as per the setup

STEPS
-----------------------
The issue can be reproduced at will with the following steps:
1. Create custom role and attach to HR
2. Open Personal Information -> Payroll
3. Click on Name

BUSINESS IMPACT
-----------------------
The issue has the following business impact:
Security breach

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms