Preview Tool

Cisco Bug: CSCvu24749 - getPolicyObjectsListByType API Calls does not work for RBAC user

Last Modified

Jun 25, 2020

Products (1)

  • Cisco Security Manager

Known Affected Releases


Description (partial)

We are using the method: getPolicyObjectsListByType

Only users who have "Full Authorization" type are able to execute the call.

Users who are using "Task Authorization" are not able to execute the call. The response is a HTTP 404, containing the error field with the string "You are not allowed to perform the requested operation". But the response contains still data.

using API with users that does not full authorization even though user has proper task authorization to perofmr that operation
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.