Hyperion EPM/FDM components database accounts: account privileges question?
This maybe a database security / data integrity related item/question for all Hyperion EPM+FDM products that connect to Oracle databases.Each Hyperion component is connecting to a separate database schema/account (using Oracle database authentication), to read/write/execute,delete, etc...But, the schema accounts have 'RESOURCE' role and some even have have 'Database-link' privileges (according to the specs).My concern: using these accounts, one may modify, drop, or delete any database object in that schema...?-Does anyone uses (or knows) any way to extra protect here: namely, to disallow any DDL statements, without breaking the Front-end components?-Does any one use synonyms/grants instead?-Anyway other way to better protect the
0