SAP Knowledge Base Article - Public

3565881 - Business User with SAP_CMD_BC_BP_DISP_PC can inexpertly display customer records while searching using the Enterprise Search in S/4HANA Public Cloud Edition 2502

Symptom

Business users assigned with only SAP_CMD_BC_BP_DISP_PC catalog can view customer details in the customer tab while using Enterprise Search to search for business partners who have customer roles assigned. The user is only supposed to have access to business partner data via Enterprise Search. This issue is of low priority, and there are no security concerns, as the business user is already authorized to view customer details through the Maintain Business Partner application.

Environment

S/4HANA Public Cloud Edition 2502

Cause

The authorization to view customer data in Enterprise Search was granted to the SAP_CMD_BC_BP_DISP_PC role via the IAM app BP_CUST_03_TRAN.

Resolution

The fix for this issue will be delivered via CE2502 HCF04 which will be delivered on the weekend of February 15th/16th.

Workaround:
To resolve this issue temporarily, deactivate the BP_CUST_03_TRAN app variant from the business role assigned to the business user.

Keywords

S4_PC, S4_1C, S/4HANA Cloud, SAP S/4HANA Cloud Public Edition, Business Partner, 2502, BP_CUST_03_TRAN, SAP_CMD_BC_BP_DISP_PC, Maintain Business Partner, Regression. , KBA , LO-MD-BP-2CL , Business Partners for Public Cloud , LO-MD-BP , Business Partners , Known Error

Product

SAP S/4HANA Cloud Public Edition 2502