SAP Knowledge Base Article - Public

3673137 - Ability to modify class ID in class details URL displays details of other class without access

Symptom

A user can manually modify the class details URL to change the class ID at the end to another and the page gives an error when they do not have access to it nor can they perform any function, but still displays the class information.

Environment

SAP SuccessFactors Learning

Reproducing the Issue

  1. Go to any class details page as front-end user
  2. On the class details page, go to the end of the browser URL and change the class ID to any that user would not have library access normally
  3. When error "You no longer have access to this Class" appears, click OK
  4. User can see the class details of another class of page preloaded, even without having library access or assigned directly

Cause

Edge case scenario where library & assignment authorizations are not applied since class ID are randomly generated on database.

Resolution

Product being enhanced to include authorization checks before backend preload on class details URL.

Targeted for 1H2026 & currently under investigation of development for patch feasibility to 2H2025

Keywords

sap, sf, successfactors, success, factors, learning, lms, class, ID, details, URL, no, longer, access, ki2505, KI2H2025 , KBA , LOD-SF-LMS-SCH , Class - Scheduled Offerings , Known Error

Product

SAP SuccessFactors Learning 2505 ; SAP SuccessFactors Learning 2511