STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must only transmit encrypted representations of passwords to the Solr Server.

DISA Rule

SV-279059r1207648_rule

Vulnerability Number

V-279059

Group Title

SRG-APP-000172-AS-000120

Rule Version

APAS-CF-000350

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the Solr package is not installed, this finding is Not Applicable.

Configure encryption to the Solr Server.

1. From the Admin Console Landing Screen, navigate to Data & Services >> Solr Server.

2. Check "Use HTTPS connection" checkbox.

3. Enter the Solr Admin HTTPS Port.

4. Select "Submit Changes".

Check Contents

If the Solr package is not installed, this is Not Applicable.

Verify encryption to the Solr Server.

From the Admin Console Landing Screen, navigate to Data & Services >> Solr Server.

If the Solr Host Name is "localhost", this is not a finding.

If the "Use HTTPS connection" setting is unchecked or "Solr Admin HTTPS Port" is zero, this is a finding.

Vulnerability Number

V-279059

Documentable

False

Rule Version

APAS-CF-000350

Severity Override Guidance

If the Solr package is not installed, this is Not Applicable.

Verify encryption to the Solr Server.

From the Admin Console Landing Screen, navigate to Data & Services >> Solr Server.

If the Solr Host Name is "localhost", this is not a finding.

If the "Use HTTPS connection" setting is unchecked or "Solr Admin HTTPS Port" is zero, this is a finding.

Check Content Reference

M

Target Key

5724