We have added search box. Key in SAP issue keyword to search

Announcement: wanna exchange links? contact me at sapchatroom@gmail.com.

Re: [sap-security] User Group Authorisation Bypassed When IDs Are Not Assinged to Valid User Groups

Posted by Admin at
Share this post:
Ma.gnolia DiggIt! Del.icio.us Yahoo Furl Technorati Reddit

Reply from Sudhakar M on May 5 at 12:56 AM
Hi Geeta,

Please follow the below steps to make the User Group Mandatory, *This will
prevent the creation of users with no user group assigned, it would assign
" User Group "Default " *

*Check if you have already implemented the Note: 1663177*

Just one line would is to be added to table USR_CUST:


Field attributes = DUMMY

Text = Default user group; due to this, the user group becomes a required
entry field (Note 1663177)


---------------Original Message---------------
From: Geetha
Sent: Monday, May 04, 2015 11:57 PM
Subject: User Group Authorisation Bypassed When IDs Are Not Assinged to Valid User Groups

Have come across a scenario, wherein access is restricted to reset password only for users mapped to User Group X.
The system responds as expected and fails when any users with User Group Y is submitted for password reset.
But the action is successful when I try to rest password for IDs that do not have a valid user group mapping.
Meaning we could change password for any user IDs without a user group mapping.
Suggestions and solutions welcome.

- G

Reply to this email to post your response.
Manage Settings | Unsubscribe | Create FAQ | Send Feedback
Copyright © 2015 Ziff Davis, LLC. and message author.
Ziff Davis, LLC. 28 E 28th Street New York, NY 10016
Sudhakar M  

Mark as helpful
View this online
Ask a new question
In the Spotlight
Earn Recognition for Your Contributions at Toolbox for IT. Gain Points for Community Achievements



Post a Comment

T r a n s l a t e to your language