Non-admin user can see Constituent notes to which they are denied access in Query

When a non-admin user creates a Constituent query this user can see Constituent Notes to which they are denied access.
Download and install the latest Service Pack which contains all fixes from previous patches. If you are running an older version, download and install the latest version and then the patch.

Steps to Duplicate

  1. Go to Administration>Security>application Users
  2. Find non-admin user
  3. Run as non-admin user
  4. Go to Analysis> Information Library
  5. Add a new Constituent query
  6. Select Criteria of Notes\Type is not blank
  7. Add to output: Notes\Type, Notes\Notes
  8. Preview Results
  9. Notice there are notes appearing with type of Confidential which this user should not have access to

Environment

 Blackbaud CRM
 4.0

Was this article helpful?