STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must set a maximum session timeout value.

DISA Rule

SV-279073r1171560_rule

Vulnerability Number

V-279073

Group Title

SRG-APP-000295-AS-000263

Rule Version

APAS-CF-000555

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Session Variable Timeout configuration.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Memory Variables.

2. Under the "Maximum Timeout" section, locate the setting for "Session Variables".

3. Set the "Session Variables" to "1" hour or fewer.

4. Select "Submit Changes".

Check Contents

Validate the Session Variable Timeout configuration.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Memory Variables.

2. Under the "Maximum Timeout" section, locate the setting for "Session Variables".

If the timeout value for Session Variables is set to greater than 1 hour, this is a finding.

Vulnerability Number

V-279073

Documentable

False

Rule Version

APAS-CF-000555

Severity Override Guidance

Validate the Session Variable Timeout configuration.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Memory Variables.

2. Under the "Maximum Timeout" section, locate the setting for "Session Variables".

If the timeout value for Session Variables is set to greater than 1 hour, this is a finding.

Check Content Reference

M

Target Key

5724