SAP Knowledge Base Article - Public

3581971 - Security concerns regarding users being able to fetch user information from other organizations from calendar view in SAP Analytics Cloud

Symptom

  • Logged-in users can fetch information from "other" organizations from calendar view.
  • Logged-in users can fetch user information from "other" organizations from profile view.

Environment

  • SAP Analytics Cloud (enterprise)

Reproducing the Issue

  1. Conduct a security audit on SAC APIs.
  2. Observe that logged-in users can fetch user information from other organizations from both calendar and profile views.

Cause

  • The role has "READ" privilege for "USER", allowing the user to read all users in the tenant via the API. This is by design.
  • SAC is a collaborative product, designed to allow users to discover other users in their list, similar to a corporate email server.
  • The reported ability to retrieve information is only possible for users who are members of the same organization.

Resolution

  1. SAC is designed to allow users to read all users in the tenant via the API.
  2. In case the current by design behaviour raises concerns it is possible to raise an enhancement request,on how to raise the request please feel free to refer to KBA - 2424376 - How do you create an enhancement request and provide feedback for SAP Analytics Cloud? - SAP for Me
    Please note that this kind of product enhancement request is discussed by the complete SAP Analytics Cloud product management team and requests that receive more votes from the community are prioritized.   

See Also

Your feedback is important to help us improve our knowledge base.

Keywords

SAP Analytics Cloud, SAC, API, security audit, vulnerability, user information, calendar view, profile view, tenant, READ privilege. , KBA , LOD-ANA-ADM , SAC Administration , Problem

Product

SAP Analytics Cloud all versions