When a service is configured to allow only a specific set of roles, but its parent folder is configured to allow public access, any user aware of the service's REST endpoint can bypass security and access the service as if it was publicly accessible.
Last Published: August 25, 2014No Product Found
Bug ID Number
NIM075654
Submitted
November 22, 2011
Last Modified
June 5, 2024
Applies to
No Product Found
Version found
10.1
Version Fixed
10.1
Status
Fixed
The bug has been fixed. See the Version Fixed and Additional Information, if applicable, for more information.
Workaround
Instead of configuring security for the service, apply the security settings to the parent folder containing the service.