STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must limit the maximum post data size.

DISA Rule

SV-279087r1171035_rule

Vulnerability Number

V-279087

Group Title

SRG-APP-000435-AS-000163

Rule Version

APAS-CF-000810

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Maximum size of post data settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Settings.

2. Set "Maximum size of post data settings" to the required amount.

3. Select "Submit Changes".

Check Contents

Verify Default Maximum size of post data settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Settings.

2. Interview the administrator to determine what the maximum post data size is required for the hosted applications.

If the "Maximum size of post data" is set to a number larger than required, this is a finding.

Vulnerability Number

V-279087

Documentable

False

Rule Version

APAS-CF-000810

Severity Override Guidance

Verify Default Maximum size of post data settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Settings.

2. Interview the administrator to determine what the maximum post data size is required for the hosted applications.

If the "Maximum size of post data" is set to a number larger than required, this is a finding.

Check Content Reference

M

Target Key

5724