We are trying to implement Pflow approvals, and we uncovered a bug where a user can access any other users Processflow Inbasket by manipulating a URL. They can then also approve Pflow work objects, and it appears as if the 'real' approver performed the approval.
Infor has acknowledged the issue and created the KB below and is developing a fix, but we do not have a concrete ETA.
My question is - has anyone else come across this in version 9 of applications, and does anyone have an alternative fix? Seems like this would impact anyone who does approvals in processflow for any purpose (Purchasing, Accounts Payable, etc) so I'm hoping maybe someone has found this and implemented their own solution.
KB article below, and step by step to replicate also below. Thanks!
https://www.inforxtreme.c...x?Solutionid=1576397
Step-by-step
1) In Lawson Portal menu on lefthand side of screen, right click on your name in Inbasket Processflow Integrator, and click “Open in New Window”
2) New window opens, with full URL at top. Change username in URL to any other Lawson user and press enter
3) The other users inbasket is now visible. You can now approve Processflow work items on their behalf, and it will appear as if the real approver was the one who clicked approve.