STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must limit the maximum number of Web Service requests.

DISA Rule

SV-279081r1171481_rule

Vulnerability Number

V-279081

Group Title

SRG-APP-000435-AS-000163

Rule Version

APAS-CF-000745

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Web Services usage.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Request Tuning.

2. Locate the "Maximum number of simultaneous Web Service requests" setting.

3. Set the value to "1" to prevent unnecessary web service threads.

4. Click "Submit Changes" to save the configuration.

Check Contents

Determine Web Services usage.

1. Interview the system administrator (SA), and/or review any of the following documentation:
- Hosted application source code.
- Hosted application design documentation.
- Published web services design documentation.
- ColdFusion baseline documentation.

2. Confirm whether Web Services are published by any hosted applications.

If Web Services are being published, this requirement is not a finding.

3. If Web Services are not being published, from the Admin Console Landing Screen, navigate to Server Settings >> Request Tuning.

4. Locate the "Maximum number of simultaneous Web Service requests" setting and verify the value is set to "1".

If Web Services are not in use and the value is not set to "1", this is a finding.

Vulnerability Number

V-279081

Documentable

False

Rule Version

APAS-CF-000745

Severity Override Guidance

Determine Web Services usage.

1. Interview the system administrator (SA), and/or review any of the following documentation:
- Hosted application source code.
- Hosted application design documentation.
- Published web services design documentation.
- ColdFusion baseline documentation.

2. Confirm whether Web Services are published by any hosted applications.

If Web Services are being published, this requirement is not a finding.

3. If Web Services are not being published, from the Admin Console Landing Screen, navigate to Server Settings >> Request Tuning.

4. Locate the "Maximum number of simultaneous Web Service requests" setting and verify the value is set to "1".

If Web Services are not in use and the value is not set to "1", this is a finding.

Check Content Reference

M

Target Key

5724