Ultra Base Navigation Allows Users to Change Their own Passwords Even Without the 'Change Password' Privilege




 
Ultra Base Navigation Allows Users to Change Their own Passwords Even Without the 'Change Password' Privilege

Date Published: Apr 11,2025 Category: Planned_First_Fix_Release:Future_Reference_Learn; Product:Blackboard_Learn_SaaS; Version:Ultra   Article No.: 000078190

Producto: Learn SaaS

Versión: SaaS

Paquetes de servicio: Ultra

Descripción: Despite the role not having the 'Personal Information > Change Password' privilege, users can still modify their passwords.

Pasos para repetir:  

  1. Log into Blackboard Learn Ultra Experience as an administrator 
  2. Go to the System Admin tab > System Roles
  3. Create a new Role called 'Password Test'
  4. Restrict all Privileges except 'Administrator Panel (Users) > Users > Edit > User Properties'
  5. Create a new user named 'Password_Test' with the Password Test Role
  6. Log into the Site as the 'Password_Test' user
  7. Click on your User Profile
  8. Scroll down to Password and click on the Change Password link
Observed Behavior: 
Able to change own password
 
Expected Behavior:
Should not be able to change own password
 

 




Versión de destino: Future Reference