<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Access Denied</title><link>https://community.appian.com/discussions/f/general/38891/access-denied</link><description>Hello All, 
 Redirected to &amp;quot;Access Denied Page&amp;quot; if I enter ../ in the text box, is this expected? 
 
 
 
 Key in../ and click on enter, then the page below is displayed, any idea why? 
 
 
 
 Application logs:</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Access Denied</title><link>https://community.appian.com/thread/149405?ContentTypeID=1</link><pubDate>Mon, 30 Jun 2025 06:43:39 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:56262381-070c-488e-8106-8b3e999e55d2</guid><dc:creator>Stefan Helzle</dc:creator><description>&lt;p&gt;Someone else reporting this issue already here. Please&amp;nbsp;open a support case.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Access Denied</title><link>https://community.appian.com/thread/149401?ContentTypeID=1</link><pubDate>Mon, 30 Jun 2025 02:44:58 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2b9c3eea-d3de-4b87-99c8-1c6baa68c14c</guid><dc:creator>ganesh.raju</dc:creator><description>&lt;p&gt;Hi Sneha Yada,&lt;/p&gt;
&lt;p&gt;I tried the same interface setup in my environment (with ../ and &amp;lt;script&amp;gt; entered in a text field), but I&amp;rsquo;m not getting redirected or seeing any error like &amp;ldquo;Access Denied.&amp;rdquo; Here&amp;rsquo;s what I&amp;rsquo;ve found:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Appian&amp;#39;s security filters like&lt;strong&gt; Web Application Firewall /XSS protection&amp;nbsp;&lt;/strong&gt;they trigger only when potentially harmful input is used in sensitive functions (e.g., file paths, safe links, or document references).&lt;/li&gt;
&lt;li&gt;The environment also matters-some environments&amp;nbsp; like hardened production instances may have stricter&amp;nbsp;&lt;strong&gt;WAF rules enabled,Extra logging or redirection layers,Older hotfixes/patches &lt;/strong&gt;where certain bugs still exist.&lt;/li&gt;
&lt;/ol&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>