STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

JVM Arguments must be configured for encryption.

DISA Rule

SV-279062r1207648_rule

Vulnerability Number

V-279062

Group Title

SRG-APP-000172-AS-000120

Rule Version

APAS-CF-000375

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure JVM Arguments for encryption.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.

2. In "JVM Arguments", enable encryption by changing any JVM Argument starting with "Dhttp.proxy" to "-Dhttps.proxy".

3. Select "Submit Changes".

4. Restart ColdFusion for the changes take effect.

Check Contents

Verify JVM Arguments are configured for encryption.

From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.

If any JVM Arguments contain the setting "Dhttp.proxyHost", this is a finding.

Vulnerability Number

V-279062

Documentable

False

Rule Version

APAS-CF-000375

Severity Override Guidance

Verify JVM Arguments are configured for encryption.

From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.

If any JVM Arguments contain the setting "Dhttp.proxyHost", this is a finding.

Check Content Reference

M

Target Key

5724