<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Minor security bug in HPE OneView</title>
    <link>https://community.hpe.com/t5/hpe-oneview/minor-security-bug/m-p/7057633#M4433</link>
    <description>&lt;P&gt;I noticed if I create a scope for a user who has access to limited amount of servers (say per location), he or she then can click on the data center tab, then click another server from the rack view that he is not authorized to see. Then after that click it takes him to the "server hardware page" then shows the list of servers from the entire infrastructure instead of just the ones he or she is authorized to see. They still don't have access to reboot or shutdown, however now they now have read only access to the entire infrastructure including SSO into the individual ilo boards.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2019 16:35:19 GMT</pubDate>
    <dc:creator>JayFromIT</dc:creator>
    <dc:date>2019-08-05T16:35:19Z</dc:date>
    <item>
      <title>Minor security bug</title>
      <link>https://community.hpe.com/t5/hpe-oneview/minor-security-bug/m-p/7057633#M4433</link>
      <description>&lt;P&gt;I noticed if I create a scope for a user who has access to limited amount of servers (say per location), he or she then can click on the data center tab, then click another server from the rack view that he is not authorized to see. Then after that click it takes him to the "server hardware page" then shows the list of servers from the entire infrastructure instead of just the ones he or she is authorized to see. They still don't have access to reboot or shutdown, however now they now have read only access to the entire infrastructure including SSO into the individual ilo boards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 16:35:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/minor-security-bug/m-p/7057633#M4433</guid>
      <dc:creator>JayFromIT</dc:creator>
      <dc:date>2019-08-05T16:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Minor security bug</title>
      <link>https://community.hpe.com/t5/hpe-oneview/minor-security-bug/m-p/7057656#M4435</link>
      <description>&lt;P&gt;The behavior you have experienced is currently by desight.&amp;nbsp; Scopes today is not designed for multi-tenant purposes, which is the behavior you are inquiring about.&amp;nbsp; All users have Read-Only access to resources on the appliance.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 20:59:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-oneview/minor-security-bug/m-p/7057656#M4435</guid>
      <dc:creator>ChrisLynch</dc:creator>
      <dc:date>2019-08-05T20:59:44Z</dc:date>
    </item>
  </channel>
</rss>

