SAP Knowledge Base Article - Preview

3228794 - Users able to access salary information even without permissions

Symptom

You notice that a user in our organization who has no RBPs to access salary information (e.g. Pay Component, Pay Group data) is able to read this data through API.
Specifically, when expanding on "empCompensationGroupSumCalculatedNav" from entity, EmpCompensation, the Compensation Group Sums will be accessible.


Read more...

Environment

SAP SuccessFactors OData API

Keywords

empCompensationGroupSumCalculatedNav, EmpCompensation, OData API, security, RBP, salary information, salary, confidential, API, expand, Pay Component, Pay Group data. , KBA , LOD-SF-INT-EC , Employee Central SFAPI & OData Entities , LOD-SF-INT-INC-ODATA , ODATA API In Integration Center , LOD-SF-INT , Integrations , LOD-SF-INT-CE , Compound Employee API , Known Error

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.