STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must have the sample data directories removed.

DISA Rule

SV-279051r1171473_rule

Vulnerability Number

V-279051

Group Title

SRG-APP-000141-AS-000095

Rule Version

APAS-CF-000275

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Delete all sample directories not referenced by an installed package in each ColdFusion instance directory.

Check Contents

1. Locate each directory of the ColdFusion instances and observe their subdirectories.

If the "db" subdirectory exists, this is a finding.

If the "cfx" subdirectory exists, this is a finding.

2. From the Admin Console Landing Screen, navigate to Package Manager >> Packages.

If the "gateway" subdirectory exists and the "eventgateways" package is not listed as installed, this is a finding.

If the "gql" subdirectory exists and the "graphqlclient" package is not listed as installed, this is a finding.

Vulnerability Number

V-279051

Documentable

False

Rule Version

APAS-CF-000275

Severity Override Guidance

1. Locate each directory of the ColdFusion instances and observe their subdirectories.

If the "db" subdirectory exists, this is a finding.

If the "cfx" subdirectory exists, this is a finding.

2. From the Admin Console Landing Screen, navigate to Package Manager >> Packages.

If the "gateway" subdirectory exists and the "eventgateways" package is not listed as installed, this is a finding.

If the "gql" subdirectory exists and the "graphqlclient" package is not listed as installed, this is a finding.

Check Content Reference

M

Target Key

5724