STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must control remote access to the Administrator Console.

DISA Rule

SV-279074r1171609_rule

Vulnerability Number

V-279074

Group Title

SRG-APP-000315-AS-000094

Rule Version

APAS-CF-000580

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Allowed IP Addresses for Console.

1. From the Admin Console Landing Screen, navigate to Security >> Allowed IP Addresses.

2. Add allowed IP addresses for accessing ColdFusion Administrator and ColdFusion Internal Directories (only IP addresses or subnets that should be capable of reaching the Administrator Console).

3. Remove any IP addresses that are blank (NULL) or set to a wildcard value.

Check Contents

Verify Allowed IP Addresses for Console.

From the Admin Console Landing Screen, navigate to Security >> Allowed IP Addresses.

If the list of allowed IP addresses is blank (NULL), is set to a wildcard value, or contains IP addresses/subnets that should not have access, this is a finding.

Vulnerability Number

V-279074

Documentable

False

Rule Version

APAS-CF-000580

Severity Override Guidance

Verify Allowed IP Addresses for Console.

From the Admin Console Landing Screen, navigate to Security >> Allowed IP Addresses.

If the list of allowed IP addresses is blank (NULL), is set to a wildcard value, or contains IP addresses/subnets that should not have access, this is a finding.

Check Content Reference

M

Target Key

5724