SAP Knowledge Base Article - Public

3212875 - Unauthorized User is Able to Perform a Change Of Stock

Symptom

A Business User is able to perform a Change Of Stock although it would not be possible due to their access rights settings.

Environment

SAP Business Bydesign

Reproducing the Issue

To check the Access Rights for a Business User:

  1. Go to Application and User Management Workcenter.
  2. Go to User and Access Management view.
  3. Go to Business Users subview.
  4. Select All Business Users then search for the relevant Business User.
  5. Click Edit then Access Rights.
  6. You check the access rights for Work Center Names PLM_QUALITYCONTROL and SCM_INTERNALLOGISTICS with Work Center View name SCM_INTLOGSCHANGEOFSTOCK and it is possible to see that the user is not authorized to perform a Change Of Stock by these settings, as the Assigned to User checkbox is not checked.

However, the relevant Business User is able to perform a Change of Stock by following the steps bellow:

  1. Login in your tenant with the relevant Business User
  2. Go to Internal Logistics workcenter
  3. Go to Change of Stock common task
  4. Perform any stock change then in Step 3 Review, click Finish
  5. You will see that it saved the change of stock performed, although it should not be permitted due to the User's Access Rights settings.

Cause

The Business User is being permitted to proceed with the Change of stock due to assignment of Workcenter View SCM_INTLOGS_GAC_OWL_WOCV.

When the WoCV SCM_INTLOGS_GAC_OWL_WOCV is unassigned, the Change of Stock stops appearing under the common tasks and the Business User is not allowed anymore to perform a Stock Change.

Resolution

If you don't want the user to perform a change of stock, unassign the relevant Business User access to Workcenter View SCM_INTLOGS_GAC_OWL_WOCV

Keywords

Access rights, Change Of Stock, Unauthorized Access, Business Users access rights , KBA , AP-IP-INV , Inventory , How To

Product

SAP Business ByDesign all versions