We have added search box. Key in SAP issue keyword to search
TopBottom

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

RE: [sap-security] User Group Authorisation Bypassed When IDs Are Not Assinged to Valid User Groups

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Reply from JimmyJ2 on May 4 at 11:58 PM
Hi Geetha,

Your experience is standard SAP functionality (working as expected).

F1 help for the user group field includes the comment "Users that are not assigned to any of the groups, can be maintained by all administrators."

Therefore all users need to be in a (non-blank) group to avoid this issue in standard SAP.

James.





James Johnson
Project Manager

---------------Original Message---------------
From: Geetha
Sent: Monday, May 04, 2015 11:57 PM
Subject: User Group Authorisation Bypassed When IDs Are Not Assinged to Valid User Groups

Have come across a scenario, wherein access is restricted to reset password only for users mapped to User Group X.
The system responds as expected and fails when any users with User Group Y is submitted for password reset.
But the action is successful when I try to rest password for IDs that do not have a valid user group mapping.
Meaning we could change password for any user IDs without a user group mapping.
Suggestions and solutions welcome.

- G

 
Reply to this email to post your response.
 
__.____._
Manage Settings | Unsubscribe | Create FAQ | Send Feedback
  
Copyright © 2015 Ziff Davis, LLC. and message author.
Ziff Davis, LLC. 28 E 28th Street New York, NY 10016
JimmyJ2  

achievements
 
Mark as helpful
View this online
Ask a new question
 
In the Spotlight
Earn Recognition for Your Contributions at Toolbox for IT. Gain Points for Community Achievements

_.____.__

0 comments:

Post a Comment

T r a n s l a t e to your language