B2B User Is Able To Access Site Which Doesn't Have a Contract Associated with the Account
(Doc ID 2554922.1)
Last updated on NOVEMBER 22, 2019
Applies to:Oracle Commerce Cloud Service - Version N/A to N/A
Information in this document applies to any platform.
B2B user (contact added in account) is able to access site which does not have a contract with that Account.
Steps to Reproduce:
- Go to https:/ccstore....com/ABC
- Login in with b2b user that has a cotract with site ABC
- Now navigate to a second site in that same session https:/ccstore....com/XYZ or select XYZ link (for which the b2b users does not have a contract)
- USER is still logged in even though the account does not have contract with XYZ
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document