My Oracle Support Banner

Participant Can See Plan Documents For Other Participants (Doc ID 2766115.1)

Last updated on APRIL 02, 2021

Applies to:

Oracle Fusion Incentive Compensation Cloud Service - Version 11.13.20.10.0 and later
Oracle Fusion Incentive Compensation - Version 11.13.20.10.0 and later
Information in this document applies to any platform.

Symptoms

The participant should only see its own compensation plan document. However, in production they can see other user's plan document.
Participant with missing party_id record can see other participant comp plan


STEPS
1. Create user REP1 in Security Console and assign role Incentive Compensation Participant
2. Login into HomePage > Sales Compensation , get errors :
    You don't have permission to access this information. Contact your help desk. (FND-13)
    OR
    You don't have permission to access this information. Contact your help desk. (FND-13)
    An application error has occurred. Your help desk can use the following information to obtain a more detailed description of this incident: Incident ID: 235, Server Domain: FADomain, Server Instance: UIServer_as1_03, Application Name: ORA_FSCM_UIAPP
3. From Navigator ( hamburger icon ) , select Incentive Compensation > Sales Compensation
    .... this user now see Plan Documents for other participants ( eg REP2 )


BUSINESS IMPACT
This is a security issue. The salesrep is able to the contract ( ie. plan document ) for other participants.

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.