STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion systems must provide clustering.

DISA Rule

SV-279069r1171551_rule

Vulnerability Number

V-279069

Group Title

SRG-APP-000225-AS-000154

Rule Version

APAS-CF-000475

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If using an external load balancer, configure and associate multiple servers behind the load balancer to ensure redundancy and high availability.

1. Confirm that the load balancer distributes traffic across all configured servers. If using ColdFusion clustering capabilities, from the Admin Console Landing Screen, navigate to Enterprise Manager >> Cluster Manager.

2. Enter a Cluster Name and click "Add".

3. Under "Actions", click the Edit icon for the new cluster.

4. Add the required servers to the cluster configuration.

5. Click "Submit" to save the cluster.

6. Edit an Existing Cluster (if applicable). Under "Actions", click the Edit icon next to the existing cluster.

7. Add additional servers to ensure the cluster contains more than one server.

8. Click "Submit" to update the configuration.

Check Contents

Verify that systems are configured to support redundancy through clustering or load balancing.

1. Confirm whether the system is designated as mission critical and requires high availability.

2. From the Admin Console Landing Screen, navigate to Enterprise Manager >> Cluster Manager.

3. Verify clusters are defined and each cluster includes more than one server.

4. If no clusters are defined or a cluster contains only one server, interview the system administrator to determine whether the server is part of an external load balancer configuration.

5. Verify that the load balancer includes multiple backend servers for redundancy.

If the system is mission critical and no clusters are configured, and the server is not part of an external load balancer with more than one backend server, this is a finding.

Vulnerability Number

V-279069

Documentable

False

Rule Version

APAS-CF-000475

Severity Override Guidance

Verify that systems are configured to support redundancy through clustering or load balancing.

1. Confirm whether the system is designated as mission critical and requires high availability.

2. From the Admin Console Landing Screen, navigate to Enterprise Manager >> Cluster Manager.

3. Verify clusters are defined and each cluster includes more than one server.

4. If no clusters are defined or a cluster contains only one server, interview the system administrator to determine whether the server is part of an external load balancer configuration.

5. Verify that the load balancer includes multiple backend servers for redundancy.

If the system is mission critical and no clusters are configured, and the server is not part of an external load balancer with more than one backend server, this is a finding.

Check Content Reference

M

Target Key

5724