STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must have sandboxes enabled and defined.

DISA Rule

SV-279065r1171383_rule

Vulnerability Number

V-279065

Group Title

SRG-APP-000211-AS-000146

Rule Version

APAS-CF-000425

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Sandbox Security.

1. From the Admin Console Landing Screen, navigate to Server Security >> Sandbox Security.

2. Check the "Enable ColdFusion Sandbox Security".

3. Create sandboxes for the applications.

4. Create a sandbox for the Administrator Console.

5. Select "Submit Changes".

Check Contents

Verify Sandbox Security.

1. From the Admin Console Landing Screen, navigate to Server Security >> Sandbox Security.

2. The Administrator Console must have a sandbox separate from the other hosted applications.

If there are no sandboxes implemented for the Administrator Console, this is a finding.

3. Sandboxes must be set up for all other hosted applications.

If there are no sandboxes implemented for other hosted applications, this is a finding.

If the "Enable ColdFusion Sandbox Security" is not checked, this is a finding.

Vulnerability Number

V-279065

Documentable

False

Rule Version

APAS-CF-000425

Severity Override Guidance

Verify Sandbox Security.

1. From the Admin Console Landing Screen, navigate to Server Security >> Sandbox Security.

2. The Administrator Console must have a sandbox separate from the other hosted applications.

If there are no sandboxes implemented for the Administrator Console, this is a finding.

3. Sandboxes must be set up for all other hosted applications.

If there are no sandboxes implemented for other hosted applications, this is a finding.

If the "Enable ColdFusion Sandbox Security" is not checked, this is a finding.

Check Content Reference

M

Target Key

5724