Execution template can be created and deleted within package states regardless of user permissions
Article ID: 84850
CA Continuous Delivery Automation - Automation Engine
Affects Release version(s): 6
Error Message :
It is possible to delete and create execution templates within package states even if the user which is logged on in Release Manager does not have the permissions for processing these tasks.
The button for deleting and creating execution templates is accessible and visible to all users. Investigation
- A user with write permission added an execution template to a Package State of Application A
- Create user B with read permissions on the folder where Application A resides.
- Login to ARA with user B, open execution template in step 1.
- User B will be able to delete the execution template even though user B only has read permissions.
Root Cause: The permissions on Release Manager to control the buttons for activities are visible/accessible regardless of permissions.
Update to a fix version listed below or a newer version if available.
Fix Status: Released
Component(s): Application Release Automation
Release Manager 7.0.0 - Available
Release Manager 6.0.2 - Available