STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must only transmit encrypted representations of passwords to the caching server.

DISA Rule

SV-279061r1207648_rule

Vulnerability Number

V-279061

Group Title

SRG-APP-000172-AS-000120

Rule Version

APAS-CF-000360

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Redis Cache encryption.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Caching.

2. Enable encryption by checking "Is SSL Enabled".

3. Select "Submit Changes".

Check Contents

Verify Redis Cache encryption.

From the Admin Console Landing Screen, navigate to Server Settings >> Caching.

If the "Redis Server" setting is "localhost" or blank, this requirement is not a finding.

If "Password" is blank, this is not a finding.

If "Is SSL Enabled" is unchecked, this is a finding.

Vulnerability Number

V-279061

Documentable

False

Rule Version

APAS-CF-000360

Severity Override Guidance

Verify Redis Cache encryption.

From the Admin Console Landing Screen, navigate to Server Settings >> Caching.

If the "Redis Server" setting is "localhost" or blank, this requirement is not a finding.

If "Password" is blank, this is not a finding.

If "Is SSL Enabled" is unchecked, this is a finding.

Check Content Reference

M

Target Key

5724