SV-279082r1171310_rule
V-279082
SRG-APP-000435-AS-000163
APAS-CF-000750
CAT II
10
1. From the Admin Console Landing Screen, navigate to Server Settings >> Request Tuning.
2. Set "Maximum number of simultaneous CFC function requests" to "1".
3. Click "Submit Changes".
Determine whether CFC functions are being called directly over HTTP or HTTPS by any hosted application. This can be verified by interviewing the system administrator (SA); or reviewing application source code, design documentation, or ColdFusion baseline documentation.
If CFC requests are used by hosted applications, this is not a finding.
1. If CFC requests are not used by hosted applications, from the Admin Console Landing Screen, navigate to Server Settings >> Request Tuning.
2. Verify " Maximum number of simultaneous CFC function requests" is set to "1".
If CFC requests are not used by hosted applications and the "Maximum number of simultaneous CFC function requests" is not set to "1", this is a finding.
V-279082
False
APAS-CF-000750
Determine whether CFC functions are being called directly over HTTP or HTTPS by any hosted application. This can be verified by interviewing the system administrator (SA); or reviewing application source code, design documentation, or ColdFusion baseline documentation.
If CFC requests are used by hosted applications, this is not a finding.
1. If CFC requests are not used by hosted applications, from the Admin Console Landing Screen, navigate to Server Settings >> Request Tuning.
2. Verify " Maximum number of simultaneous CFC function requests" is set to "1".
If CFC requests are not used by hosted applications and the "Maximum number of simultaneous CFC function requests" is not set to "1", this is a finding.
M
5724