STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must transmit only encrypted representations of passwords to NoSQL data sources.

DISA Rule

SV-279058r1207648_rule

Vulnerability Number

V-279058

Group Title

SRG-APP-000172-AS-000120

Rule Version

APAS-CF-000345

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. From the Admin Console Landing Screen, navigate to Data & Services >> NoSQL Data Sources.

2. Make the necessary changes to the data source to use encryption.

3. Check " Enable SSL" checkbox.

4. Select "Submit".

Check Contents

1. From the Admin Console Landing Screen, navigate to Data & Services >> NoSQL Data Sources.

2. For each "Connected NoSQL Data Source" configured, examine the settings and verify if encryption is enabled and properly configured for each data source connection.

If any NoSQL data source is found without encryption enabled, this is a finding.

If any NoSQL data source does not have "Enable SSL " checked, this is a finding.

Vulnerability Number

V-279058

Documentable

False

Rule Version

APAS-CF-000345

Severity Override Guidance

1. From the Admin Console Landing Screen, navigate to Data & Services >> NoSQL Data Sources.

2. For each "Connected NoSQL Data Source" configured, examine the settings and verify if encryption is enabled and properly configured for each data source connection.

If any NoSQL data source is found without encryption enabled, this is a finding.

If any NoSQL data source does not have "Enable SSL " checked, this is a finding.

Check Content Reference

M

Target Key

5724