SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 43035: A user ID with only View permission can edit an incident

DetailsHotfixAboutRate It

In SAS® Enterprise GRC, both role permissions and your assigned location determine what tasks you can perform. It is common for user IDs to have different roles based on location.

If you have the following application configuration setting:

monitor.incidentComponentSecurity.ignored=true
permissions might be assigned to you for an incorrect location.


For example, you might have the following role permissions and locations that are assigned to you:

   Role Name                 Location
   ========================  =====================
   View Incident             Credit Card Division
   View and Update Incident  Bank Branch 1

In the example above, you are incorrectly able to update incidents in the Credit Card Division even though your role permission is view-only for that location. Updates occur because you have Update permissions on Bank Branch 1, and your configuration setting is set to true, as noted above.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Enterprise GRCMicrosoft® Windows® for x644.25.19.2 TS2M39.3 TS1M0
Microsoft Windows Server 2003 Datacenter Edition4.25.19.2 TS2M39.3 TS1M0
Microsoft Windows Server 2003 Enterprise Edition4.25.19.2 TS2M39.3 TS1M0
Microsoft Windows Server 2003 Standard Edition4.25.19.2 TS2M39.3 TS1M0
Microsoft Windows Server 2003 for x644.25.19.2 TS2M39.3 TS1M0
Microsoft Windows Server 20084.25.19.2 TS2M39.3 TS1M0
Microsoft Windows Server 2008 for x644.25.19.2 TS2M39.3 TS1M0
Microsoft Windows XP Professional4.25.19.2 TS2M39.3 TS1M0
Windows 7 Enterprise 32 bit4.25.19.2 TS2M39.3 TS1M0
Windows 7 Enterprise x644.25.19.2 TS2M39.3 TS1M0
Windows 7 Home Premium 32 bit4.25.19.2 TS2M39.3 TS1M0
Windows 7 Home Premium x644.25.19.2 TS2M39.3 TS1M0
Windows 7 Professional 32 bit4.25.19.2 TS2M39.3 TS1M0
Windows 7 Professional x644.25.19.2 TS2M39.3 TS1M0
Windows 7 Ultimate 32 bit4.25.19.2 TS2M39.3 TS1M0
Windows 7 Ultimate x644.25.19.2 TS2M39.3 TS1M0
Windows Vista4.25.19.2 TS2M39.3 TS1M0
Windows Vista for x644.25.19.2 TS2M39.3 TS1M0
64-bit Enabled AIX4.25.19.2 TS2M39.3 TS1M0
64-bit Enabled Solaris4.25.19.2 TS2M39.3 TS1M0
HP-UX IPF4.25.19.2 TS2M39.3 TS1M0
Linux for x644.25.19.2 TS2M39.3 TS1M0
Solaris for x644.25.19.2 TS2M39.3 TS1M0
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.