Symptom
- Multiple supplier complaint types are configured, each with a QualityManager role (read/write) and a QualityAudit role (read-only).
- A user assigned QualityManager for one complaint type and QualityAudit for a different complaint type can create and edit complaints for the type where only read-only access should apply.
- The system restricts user access based on a combination of Plant, CompanyCode, Supplier, PurchaseOrganization, SupplierComplaintType, and SupplierItemCategory attributes (refer to link in See also).
- Users receive unintended write permissions across complaint types they should not be able to edit.
- No error messages are shown.
Read more...
Environment
SAP Complaint Handling
Product
SAP Complaint Handling all versions
Keywords
supplier complaints, complaint type, qualitymanager, qualityaudit, read-only allows edit, role collection, union of permissions, unrestricted attribute, suppliercomplainttype, authorization leak, access control, cmh, btp roles, role attributes, permissions scope , KBA , LOD-DMO-CMH , SAP Complaint Handling , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview