ColdFusion must be using an enterprise solution for authentication.
DISA Rule
SV-279055r1171527_rule
Vulnerability Number
V-279055
Group Title
SRG-APP-000149-AS-000102
Rule Version
APAS-CF-000310
Severity
CAT I
CCI(s)
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000162 - Protect audit information from unauthorized access.
- CCI-000164 - Protect audit information from unauthorized deletion.
- CCI-001499 - Limit privileges to change software resident within software libraries.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-001954 - Electronically verifies Personal Identity Verification-compliant credentials.
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002010 - Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
Weight
10
Fix Recommendation
Configure LDAP.
1. From the Admin Console Landing Screen, navigate to Security >> Administrator >> External Authentication" tab.
2. Configure LDAP:
- Select "LDAP" option.
- Click "Edit LDAP Configuration".
- Enter LDAP Details.
- Click "SAVE".
3. If connection is verified, click "Submit Changes".
Check Contents
Verify LDAP is in use.
From the Admin Console Landing Screen, navigate to Security >> Administrator.
If "External Authentication" is set to "NONE", this is a finding.
Vulnerability Number
V-279055
Documentable
False
Rule Version
APAS-CF-000310
Severity Override Guidance
Verify LDAP is in use.
From the Admin Console Landing Screen, navigate to Security >> Administrator.
If "External Authentication" is set to "NONE", this is a finding.
Check Content Reference
M
Target Key
5724