New Apps User defaults with all User Edition Privileges - Security Breach?

Please check the following Scenario/Issue and please let me know if anyone has a solution for it.
1. In Apps, created following Responsibilities
- Payables Inquiry-Only User
- Projects Inquiry-Only User
2. In Discoverer Admin, Tools->Privileges, assigned following privilege to "Payables Inquiry-Only User"
- User Edition Parent only (unchecked all child privileges such as Create/Edit Query)
3. In Discoverer Admin, Tools->Security, mapped following Responsibilities/Business Areas (BA)
- Resp: Payables Inquiry-Only User BA: AP Payables
- Resp: Projects Inquiry-Only User BA: PA Projects
4. In Apps, created user DISC_INQUIRY_USER, assigned following responsibilities
- Payables Inquiry-Only User
- Projects Inquiry-Only User
5. At this stage, if user connects to User Edition;
- user is able to create new query in BA: AP Payables or BA: PA Projects depending on login Responsibility
- By default Discoverer assigns all User Edition Privileges to new Apps User including Create/Edit Query
Requirement
1. Create new Apps User DISC_INQUIRY_USER, assign it Inquiry-Only Responsbilities
2. Login to User Edition - DISC_INQUIRY_USER: Payables Inquiry-Only User
- User can inquiry Workbooks associated with Resp: Payables Inqiry-Only user
- Should not be able to create new workbooks
3. Login to User Edition - DISC_INQUIRY_USER: Projects Inquiry-Only User
- User can inquiry Workbooks associated with Resp: Projects Inquiry-Only User
- Should not be able to create new workbooks
Issue
There is time-gap between creating Apps User and login to Discoverer Admin to remove user privileges. This is security Breach, is their any way to change get around it.
- Discoverer gives precedence to Responsibility Privileges over User Privileges. Is their any way to change it?
- Is it possible to change default Privileges for new Apps User?
- I am facing this issue in Discoverer 4.1.48, Does discoverer Admin behaves differently in latest Versions?

Nobody helps you except yourself. ;)
So, this query get privileges for user PUBLIC
select eap.ap_id, eap.gp_app_id
from eul5_eul_users eeu,
eul5_access_privs eap
where eeu.eu_username = 'PUBLIC'
and eap.ap_eu_id = eeu.eu_id
and eap.ap_type = 'GP'
In my case
3001     1000
3002     1001
3003     1002
3004     1003
3005     1004
3006     1005
3015     1013
3016     1014
3017     1018
3018     1024
I research а corresponding between gp_app_id (second column) and real name of privilege and get the next list:
1000     Discoverer and Plus Privilege
1001     Create/Edit Query
1002     Item Drill
1003     Drill Out
1004     Grant Workbook
1005     Collect Query Statistics
1006     Administration Privilege
1007     Set Privilege
1008     Create/Edit Business Area
1009     Format Business Area
1010     Create/Edit Summaries
1012     Schedule Workbook
1013     Unknown
1014     Save Workbooks to Database
1015     Manage Scheduled Workbooks
1018     Unknown
1024     Create Link
So, the ID of privilege 'Save Workbooks to Database' is 1014. This privilege exists in table in spite of in Discoverer Administrator this option UNCHECK for user PUBLIC.
This is a REAL BUG!!!
Then I executed query
delete from eul5_access_privs where ap_id = 3016
and after that all became right.
Now please explain me this bug. And I have question - which privileges have IDs 1013 and 1018?
Thank you.

Similar Messages

  • I created new users on my mac and my music, photos, etc. is still on the administrators account. How can I share them with all users?

    I created new users on my mac and my music, photos, etc. are all still on the administrators account. I tried making the other 2 new accounts administrators but that didn't work. How can I share them with all users?

    Read "iTunes: Setting up Home Sharing on your computer."

  • How to make custom append search help tab default for all users?

    I've implemented my own search help append and I need to make the F4 search help to display my tab as default for all users. I know that search help stores the last tab used by the user in memory and when user uses the search help next time the last used tab is displayed but I have to make the system display the tab od my search help append always as default tab. Any idea how to do it?
    Message was edited by:
            Marcin Milczynski

    hi
    <b>Enhancement using Append structures</b>
        Append structures allow you to attach fields to a table without actually having to modify the table itself. You can use the fields in append structures in ABAP programs just as you would any other field in the table.
    Click on the append structure tab and opt to create new
    structure.
    Append structures allow you to enhance tables by adding fields to them that are not part of the standard. With append structures; customers can add their own fields to any table or structure they want.
    Append structures are created for use with a specific table. However, a table can have multiple append structures assigned to it
        Customers can add their own fields to any table or structure they want.
    The customer creates append structures in the customer namespace. The append structure is thus protected against overwriting during an upgrade. The fields in the append structure should also reside in the customer namespace, that is the field names should begin with ZZ or YY. This prevents name conflicts with fields inserted in the table by SAP

  • ITunes Shared library with all users on one computer

    I am trying to share my iTunes (version 8.2) library with all the users on my computer. So far, this is what I have done:
    1) I have moved the music folder into the shared folder.
    2) I have selected "Add to Library" in all three accounts.
    3) I have tried checking and unchecking the "Copy files to iTunes Music folder when adding to library."
    Since then, I have added some CDs that had some songs that I already had. When I loaded these CDs, I deleted the duplicates that had the worse sound. Since then, everything is unwinding. The additions on one user account are not being added to the others. When I delete a track, iTunes (obviously) says that it can't find the song anymore. What's odd is that I then delete the one that is missing, and both are missing now: the one that I deleted on the original account and the one that I did not delete on the original account.
    I am starting to think that I need to start from scratch. So, to make a long story short (too late), how can I share my iTunes library with all users on one computer, where I can make a change in one account that will update automatically on the other accounts. If it can't be updated automatically, how can I add/delete files without causing the headaches I am currently having?
    Brian

    I actually followed this, but I still had problems that I listed above. Is there any way that when you make changes to one account (even if there is only one main account where changes are made), the changes are automatically (or at least easily) applied to the other user accounts?

  • HT1527 I have windows 8.1 and cannot access itunes store even creating a new apple id. With other users on the same computer I can access itunes store. How can I solve this?

    I have windows 8.1 and cannot access itunes store even creating a new apple id. With other users on the same computer I can access itunes store. How can I solve this?

    i had the same problem before using a fresh install of Windows 8.1.  I have resolved this issue by running the program compatibility wizard.  This I did by right-clicking on the iTunes icon in the desktop, selecting Troubleshoot compatibility, waited for it to detect compatibility issues and when presented with the following options: 1.) Try recommended settings; 2.) Troubleshoot program, I chose the latter.  When asked what problems I noticed, I checked the following: "The program worked in earlier versions of Windows but won't install or run" and "The program requires additional permission"
    After that, it tired to resolve the issue, and provided the necessary settings to run iTunes.  Now it's running flawlessly.  I have Avast anti-virus installed though.
    HTH!

  • How do i get that little pop up menu with all the editing choices on it that i used to get?  Is there a way to get the editing box to pop up as I make a new event instead of editing an event after i just made it ??????

    How do i get that little pop up menu with all the editing choices on it that i used to get?  Is there a way to get the editing box to pop up as I make a new event instead of editing an event after i just made it ??????

    Michal,
    iCal Help is a good place to start. Here are a couple of examples:

  • Enable save for all users in rich client document defaultly for all users

    Hi,
    Is there a option to enable save for all users in a rich client document defaultly for all users across the company. As the users who are creating reports are forgetting to check the box before sending the rich client document to others. Kindly let me know if you have any suggestions on this.
    Thanks,
    Karthik

    I'd suggest that is is where your BO folder structure comes in. You can export from Rich Client to any folder that you have permissions to access - some sort of collaboration folder system would potentially be better and more secure than sending unsecured reports via email. If your IT security team found out that you were removing document security, I doubt they'd be impressed!
    You can't do the default save for all users, simple as that (it's bad practice anyway, which is probably why you can't). While it's not the answer that you want to hear, it is the correct one.

  • User Role with All MM Transaction codes

    Hi SAP Gurus,
    I need to create a User role with all MM transactions.  Can anyone please let me know whether Standard User role is available which has authorisations for all MM transaction codes ?  If yes, what is the User role name.  If not, what is the easiest way to get a list of all MM transaction codes.
    Regards,
    Janagiraman.

    Hi,
    sap_mm_all role name is not available in client sap system version 5.0.  The role might have been deleted by someone.
    Regards,
    Janagi

  • Is GB 9.0.4 update today at App Store needed for all users, or just for Lion? Will it be in Software Update or is it paid update only? Please clarify

    Is the GB 9.0.4 update today at App Store needed for all users, or just for Lion? Will it be in Software Update or is it paid update only? Please clarify.

    I sure hope you are correct, Christoph. Seems one Mac site has questioned this also:
    http://www.tuaw.com/2011/07/11/iphoto-garageband-and-imovie-updated-in-mac-app-s tore/
    No iWeb updates either way so far. Not that I use it, just an observation.

  • Google drive does not work with specific group but works with all users group!!

    Hi,
    Why Google drive does not work with specific group but works with all users group?
    My rule :  Internal > external > all users = works fine
    But
                   Internal > external > A group = not working !!

    Hi,
    if you require user authentication in Firewall policy rules, the clients must bei Webproxy clients (for HTTP / HTTPS) or TMG clients (for TCP/UDP):
    http://technet.microsoft.com/en-us/library/bb794762.aspx
    regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.galileocomputing.de/3276?GPP=MarcGrote

  • I backed up my new iPod touch with data from my old one. This seems to have erased all the new apps that came with the new iPod. What do I do now?

    I got a new iPod Touch today. I wanted to transfer all my apps and data over to the new iPod from my old one, so I restored it from my old one. Unfortunately, it seems to have erased the new apps that come with the latest iPod. What do I do to get the back?

    Maybe I'm confusing apps with function. I was looking at the features on Apple's site, and it showed Voice Control, Air Print, Air Play, that sort of thing.

  • How to reset the wiki server (MAC OS X 10.9 with OS X Server App Version 3) with all wiki datas only

    Hi,
    I need to reset my Wiki on MAC OS X 10.9 with OS X Server App Version 3, but without reinstalling the whole server app to configure all services.
    Does anybody knows how to reset the wiki server (MAC OS X 10.9 with OS X Server App Version 3) with all wiki datas only.
    Thanks a lot for your hints

    Hi Linc,
    sorry, I haven't saved the System-Logfile before restoring my parallels VM.
    But it looks like issues of linking data.
    For testing the Server services I have done a reset for a user password and I have deleted the profiles and configuration from Client-Side. One with Mac OS X 10.9.1, one iPad with iOS 6.1.3. But it was not possible to reconfigure/reinstall the Server Profile. Also a manually configuration was odd, because for some services the new password was necessary and for other services the old password. Very strange.
    To bring back the services I have rolled back the last snapshot of my parallels VM. Afterwards there was no probleme to reconfigure/reinstall the Profile on Client-Side (OS X 10.9.1 and iOS 6.1.3). Also the manually configuration shows the password for all services are matching with the current configuration.
    I'm going to install a further parallels VM with Mac OS X 10.9.1 and Server App 3 from scratch to move the services.
    Greetings

  • HT201210 I upgraded from iPhone 3G to 4S a few days ago. I choose the option to restore from my last 3G backup. It worked fine but I just realized that I do not have the new apps which come with the 4S. What should I do? Thanks for any help. Léo

    I upgraded from iPhone 3G to 4S a few days ago. When setting up the new 4S, I choose to restore my last 3G backup. It started by updating the OS to version 5.1 (9B179) then restored my apps and setting. Everything went well except that I realized I do not have the new apps which come with the 4S, like FaceTime, HD video and Siri.
    What should I do to correct this?
    Thank you in advance for any help on this.

    Ah, FaceTime is not an app, either. It's accessed by tapping the FaceTime button when you are in the contacts app and have selected a contact. This can also be done from the Phone app under the Contacts tab, or during a call, you can switch to FaceTime.
    Let me know what other apps/features you are missing.

  • How can I repair my IPod n still have all my information in it or can i get a new one but still with all my information for how much?

    How can I repair my IPod n still have all my information in it or can i get a new one but still with all my information for how much

    - Apple will exchange your iPod for a refurbished one for this price. They do not fix yours. Apple does not transfer any data.
    Apple - iPod Repair price      
    - To backup all your data to computer follow the instructions here. However, do not restore from backup until you have the replacement/repaired iPod.

  • I have a Kindle and have just purchased 4 new e-books - downloaded with Adobe Digital Editions. Now how do I get them on my Kindle?

    I have a Kindle and have just purchased 4 new e-books - downloaded with Adobe Digital Editions. Now how do I get them on my Kindle?

    To remove the book simply touch and hold the cover on the main page.  A little pop up will ask, remove?  Say yes.  The book content will de deleted.   The cover will remain on your main page with a little down arrow so that you can redownload it if you wan in the cloud view.  In the device view, it simply disappears.
    Note at the bottom of the page are a couple of switches, labeled cloun and device.  The device switch shows you books on your device.  The cloud page shows your whole catalog, and the down arrow allows you to bring down anything in your catalog to the device.

Maybe you are looking for