Hi Abhishek
"It seems that steps after upgrade i.e. tcode SU25 were not executed" - seems you have answered your question?
That aside, debugging and finding AGR_1251 tables means you just found PFCG role contents. As Julius has advised - have your security team fix the role
In addition, if you think SU25 is contibuting (therefore SU24) you might want to check table USBOT_C and see if there are any S_ALV_LAYO values for ACTVT 03. Have security fix them and adjust all impacted roles. If, however, the PFCG entry (AGR_1251) is manually added to the role, then security need to go manually fix it.
In short, talk to your security team.
Regards
Colleen