STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must configure WebSocket Service.

DISA Rule

SV-279040r1171341_rule

Vulnerability Number

V-279040

Group Title

SRG-APP-000141-AS-000095

Rule Version

APAS-CF-000190

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure ColdFusion WebSocket.

1. From the Admin Console Landing Screen, navigate to Server Settings >> WebSocket.

2. If "Use Proxy" is selected, uncheck "Port" to disable non-SSL WebSocket connections. Non-SSL WebSocket is not permitted.

3. If "Use Built-in WebSocket Server" is selected, uncheck "Port" to disable non-SSL WebSocket connections. Non-SSL WebSocket is not permitted.

4. Enable encryption by checking "SSL Port" and enter an approved port value.

5. Enter keystore and password.

6. Uncheck the "Start Flash Policy Server".

7. Set the "Max Data Size" to the default setting of 1024 or to the required maximum size for the hosted applications.

8. Select "Submit Changes".

Check Contents

Verify the ColdFusion WebSocket configuration.

1. From the Admin Console Landing Screen, navigate to Server Settings >> WebSocket.

If the "websocket" package is not installed, this is Not Applicable.

2. If "Enable WebSocket Service" is checked:
If "Use Proxy" is selected and the "Port" setting is checked, this is a finding. Non-SSL WebSocket is not permitted.

3. If "Use Built-in WebSocket Server" is selected and the "Port" setting is checked, this is a finding. Non-SSL WebSocket is not permitted.

4. If SSL Port is not checked, this is a finding.

5. Verify SSL Port is an approved port. If not, this is a finding.

6. If "Start Flash Policy Server" is checked, this is a finding.

7. If "Max Data Size" is over the required maximum size, this is a finding.

Vulnerability Number

V-279040

Documentable

False

Rule Version

APAS-CF-000190

Severity Override Guidance

Verify the ColdFusion WebSocket configuration.

1. From the Admin Console Landing Screen, navigate to Server Settings >> WebSocket.

If the "websocket" package is not installed, this is Not Applicable.

2. If "Enable WebSocket Service" is checked:
If "Use Proxy" is selected and the "Port" setting is checked, this is a finding. Non-SSL WebSocket is not permitted.

3. If "Use Built-in WebSocket Server" is selected and the "Port" setting is checked, this is a finding. Non-SSL WebSocket is not permitted.

4. If SSL Port is not checked, this is a finding.

5. Verify SSL Port is an approved port. If not, this is a finding.

6. If "Start Flash Policy Server" is checked, this is a finding.

7. If "Max Data Size" is over the required maximum size, this is a finding.

Check Content Reference

M

Target Key

5724