Appian Community
Site
Search
Sign In/Register
Site
Search
User
DISCUSS
LEARN
SUCCESS
SUPPORT
Documentation
AppMarket
More
Cancel
I'm looking for ...
State
Verified Answer
+3
person also asked this
people also asked this
Replies
14 replies
Subscribers
10 subscribers
Views
13100 views
Users
0 members are here
Share
More
Cancel
Related Discussions
Home
»
Discussions
»
Administration
Security Attacks in Appian
sachitanands1
over 8 years ago
Are Appian Applications vulnerable to SQL Injection and Cross site scripting attacks? Yes/No why?
OriginalPostID-263116
Discussion posts and replies are publicly visible
Top Replies
Parmida Borhani
over 7 years ago
in reply to
garym
+2
verified
Appian Employee
SQL injection protection is more about how you interact with the database than with how you collect data in a form. Whenever you interact with a database using Appian's out-of-the-box database functionality…
Parents
0
chetany
A Score Level 1
over 8 years ago
Appian collaborates with a third party for penetration and vulnerability testing. Check this link:
forum.appian.com/.../Appian_Cloud_FAQ.html
Companies using Appian can still carry out penetration testing on their own, but they need to notify Appian - if they are doing it on Appian cloud env.
Also, Appian uses SAIL - data submitted on SAIL forms is sent/received in encrypted format to some extent. There are extensive checks that happen at the server side.
Also, I think "Cross site scripting" is not likely - because Appian does not allow JavaScript/Ajax for creating UI. Such kind of attacks are more likely when the UI is being developed in JS/Ajax.
There is one place where JS/Ajax gets used - in Embedded SAIL. However, that too is unlikely - because the admin needs to allow IP addresses/hosts for CORS in Appians "Allowed CORS hosts " in the admin console.
So, overall I think such attacks are very unlikely with Appian.
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel
Reply
0
chetany
A Score Level 1
over 8 years ago
Appian collaborates with a third party for penetration and vulnerability testing. Check this link:
forum.appian.com/.../Appian_Cloud_FAQ.html
Companies using Appian can still carry out penetration testing on their own, but they need to notify Appian - if they are doing it on Appian cloud env.
Also, Appian uses SAIL - data submitted on SAIL forms is sent/received in encrypted format to some extent. There are extensive checks that happen at the server side.
Also, I think "Cross site scripting" is not likely - because Appian does not allow JavaScript/Ajax for creating UI. Such kind of attacks are more likely when the UI is being developed in JS/Ajax.
There is one place where JS/Ajax gets used - in Embedded SAIL. However, that too is unlikely - because the admin needs to allow IP addresses/hosts for CORS in Appians "Allowed CORS hosts " in the admin console.
So, overall I think such attacks are very unlikely with Appian.
Cancel
Vote Up
0
Vote Down
Sign in to reply
Verify Answer
Cancel
Children
No Data