STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Web services using Simple Object Access Protocol (SOAP) to access sensitive data must be secured with WS-Security.

DISA Rule

SV-279056r1171606_rule

Vulnerability Number

V-279056

Group Title

SRG-APP-000156-AS-000106

Rule Version

APAS-CF-000325

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure web services using the SOAP protocol to access sensitive data.

1. Install and configure the WS-Security suite to secure access to the sensitive data.

2. Ensure the configuration provides:
- Authentication of service consumers.
- Message integrity (e.g., via XML signatures).
- Confidentiality (e.g., via encryption).

3. Update application and service documentation to reflect the WS-Security implementation.

Check Contents

Verify that web services using the SOAP protocol to access sensitive data are secured with WS-Security.

1. Determine Web Services Usage by interviewing the system administrator (SA), or reviewing relevant documentation, including:
- Hosted application source code.
- Application design documentation.
- Published web services design documentation.
- ColdFusion baseline documentation.

2. Evaluate Applicability.

If no web services are published, this requirement is not a finding.

If web services are published and the SOAP protocol is not used, this is not a finding.

If SOAP is used and the data accessed is not sensitive, this requirement is not a finding.

3. Verify Security Controls. If web services are published using SOAP to access sensitive data:

a. Confirm that WS-Security is implemented to provide secure authentication and protect the data.

b. This may be verified by interviewing the administrator or reviewing the documentation sources listed above.

If web services are published using SOAP to access sensitive data and WS-Security is not implemented, this is a finding.

Vulnerability Number

V-279056

Documentable

False

Rule Version

APAS-CF-000325

Severity Override Guidance

Verify that web services using the SOAP protocol to access sensitive data are secured with WS-Security.

1. Determine Web Services Usage by interviewing the system administrator (SA), or reviewing relevant documentation, including:
- Hosted application source code.
- Application design documentation.
- Published web services design documentation.
- ColdFusion baseline documentation.

2. Evaluate Applicability.

If no web services are published, this requirement is not a finding.

If web services are published and the SOAP protocol is not used, this is not a finding.

If SOAP is used and the data accessed is not sensitive, this requirement is not a finding.

3. Verify Security Controls. If web services are published using SOAP to access sensitive data:

a. Confirm that WS-Security is implemented to provide secure authentication and protect the data.

b. This may be verified by interviewing the administrator or reviewing the documentation sources listed above.

If web services are published using SOAP to access sensitive data and WS-Security is not implemented, this is a finding.

Check Content Reference

M

Target Key

5724