STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must not store user information in the server registry.

DISA Rule

SV-279084r1171578_rule

Vulnerability Number

V-279084

Group Title

SRG-APP-000435-AS-000163

Rule Version

APAS-CF-000760

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Client Variable settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Client Variables.

2. Set the default storage mechanism for client sessions to any available mechanism other than the registry.

3. Set "Purge Interval" to 1 hour and 7 minutes.

4. Select "Apply".

Check Contents

Verify Client Variable Settings.

From the Admin Console Landing Screen, navigate to Server Settings >> Client Variables.

If the default storage mechanism for client sessions is set to "Registry", this is a finding.

If the "Purge Interval" is not set to 1 hour and 7 minutes, this is a finding.

Vulnerability Number

V-279084

Documentable

False

Rule Version

APAS-CF-000760

Severity Override Guidance

Verify Client Variable Settings.

From the Admin Console Landing Screen, navigate to Server Settings >> Client Variables.

If the default storage mechanism for client sessions is set to "Registry", this is a finding.

If the "Purge Interval" is not set to 1 hour and 7 minutes, this is a finding.

Check Content Reference

M

Target Key

5724