Bug ID 613373: Access may be denied to users with Application Editor role when accessing SAML Authentication Context UI page

Last Modified: Apr 10, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP APM(all modules)

Known Affected Versions:
11.5.1, 11.5.1 HF1, 11.5.1 HF10, 11.5.1 HF11, 11.5.1 HF2, 11.5.1 HF3, 11.5.1 HF4, 11.5.1 HF5, 11.5.1 HF6, 11.5.1 HF7, 11.5.1 HF8, 11.5.1 HF9, 11.5.2, 11.5.2 HF1, 11.5.3, 11.5.3 HF1, 11.5.3 HF2, 11.5.4, 11.5.4 HF1, 11.5.4 HF2, 11.5.4 HF3, 11.5.4 HF4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1

Fixed In:
13.0.0, 12.1.3.2

Opened: Aug 30, 2016
Severity: 3-Major

Symptoms

When accessing the SAML Authentication Context UI page with application editor user role, the following error will be displayed: Read Access Denied: user (username) type (SAML authentication context classes list)

Impact

SAML Authentication Context UI page will not display existing objects

Conditions

User attempting to view the page belongs to application editor group/role

Workaround

SAML Authentication Context UI page will still show existing object for users with administrative role.

Fix Information

With the fix, no errors will be shown to users with Application Editor role when accessing SAML Authentication Context UI page

Behavior Change